{"id":"MGASA-2014-0074","summary":"Updated libgadu packages fix security vulnerability","details":"A malicious server or man-in-the-middle could send a large value for\nContent-Length and cause an integer overflow which could lead to a buffer\noverflow in Gadu-Gadu HTTP parsing (CVE-2013-6487).\n","modified":"2026-04-16T01:47:18.242719080Z","published":"2014-02-16T13:23:36Z","upstream":["CVE-2013-6487"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0074.html"},{"type":"WEB","url":"http://libgadu.net/releases/1.11.3.html"},{"type":"WEB","url":"http://www.debian.org/security/2014/dsa-2852"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=12709"}],"affected":[{"package":{"name":"libgadu","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/libgadu?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.11.3-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0074.json"}},{"package":{"name":"libgadu","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/libgadu?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.11.3-1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0074.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}