also @ TechSpot: Desktop Core i3 Ivy Bridge CPUs leaked ahead of launch
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.

Go Back   TechSpot OpenBoards > TechSpot Community > General Discussion

Collaborate in the cloud with Office, Exchange, SharePoint, and Lync

Multiple Vulnerabilities in ICQ

Thread Tools Search this Thread
  #1  
Old 05-06-2003
TS | Thomas's Avatar
TechSpot Maniac
 
Location: Ireland
Member since: Feb 2002, 1,327 posts
Multiple Vulnerabilities in ICQ

Vulnerable Packages: Mirabilis ICQ Pro 2003a & previous versions.

6 security vulnerabilities were found that could lead to various forms of exploitation ranging from denying users the ability to use ICQ services to execution of arbitrary commands on vulnerable systems. The following vulnerabilities were found:

POP3 Client Format String in UIDL Field.
"Subject" signed overflow in POP3 Client.
"Date" signed overflow in POP3 Client.
ICQ Features on Demand spoofing attack.
Message advertisements denial of service attack.
Input validation error in ICQ's GIF parsing/rendering library.

Vendors contacted:
- Mirabilis
We sent notifications mails to the following addresses: security@icq.com, secure@icq.com, webmaster@icq.com, support@icq.com, several times during March & April (2003-03-11, 2003-03-24, 2003-04-11) & never received an answer from Mirabilis.

Would you like to know more? Seems Mirabilis also attended the same classes as Microsoft on "How to handle security vulnerabilty reports for your products".
  #2  
Old 05-07-2003
Mictlantecuhtli's Avatar
TechSpot Special Forces
 
Location: Finland
Member since: Feb 2002, 4,886 posts
System specs
Only affects Windows versions?
  #3  
Old 05-08-2003
TS | Thomas's Avatar
TechSpot Maniac
 
Location: Ireland
Member since: Feb 2002, 1,327 posts
The posting they have up doesn't say anything beyond "Vulnerable Packages: Mirabilis ICQ Pro 2003a & previous versions". I'd presume from some of the descriptions though it wouldn't just be limited to windows versions
Closed Thread

Similar Topics
Topic Replies Forum
Vulnerabilities in TCP 0 General Discussion
Three more Critical Windows Vulnerabilities 0 General Discussion
Multiple Vulnerabilities in Half-Life 3 General Discussion
Multitude of Unreal Engine Vulnerabilities 2 General Discussion
Windows XP vulnerabilities 0 General Discussion

Thread Tools Search this Thread
Search this Thread:

Advanced Search
All times are GMT -4. The time now is 05:18 AM.