Software flaws & virus bulletin:
Release date: 2003-5-8
Affected program: ICQ Pro 2003a and earlier versions
Detailed description:
Mirabilis ICQ is a very popular instant messaging program, with functions such as chatting, sending email, SMS, and wireless pager messages. ICQ has six flaws that can cause users to be unable to use ICQ normally, and allow attackers to execute arbitrary code on the target user's system:
1. POP3 Client format string flaw:
ICQ's POP3 client has a format string flaw in the UIDL command server response, which can allow an attacker to impersonate a POP3 server.
2. POP3 Client “Subject” buffer overflow flaw:
ICQ's POP3 client has a buffer overflow flaw when processing the “Subject” field of an EMAIL header. This flaw is triggered if the EMAIL subject contains more than 16 bits of characters. By sending a carefully crafted malicious EMAIL subject to the target user, an attacker can execute arbitrary commands on the target user's machine.
3. POP3 Client “Date” buffer overflow flaw:
ICQ's POP3 client has a buffer overflow flaw when processing the “Date” field of an EMAIL header. This flaw is triggered if the EMAIL subject contains more than 16 bits of characters. By sending a carefully crafted malicious EMAIL subject to the target user, an attacker can execute arbitrary commands on the target user's machine.
4. ICQ “Features on Demand” spoofing attack:
ICQ can auto-upgrade by calling the “ICQ Features on Demand” function. Because the program lacks proper authentication and uses hard-coded information, an attacker can use spoofing methods to install malicious programs on the target user's machine and execute arbitrary code.
5. Message announcement DoS attack:
The dedicated HTTP parsing/display library ICQ uses to display message announcements in the message window has a flaw when parsing tag input. By impersonating a static ADS server and sending carefully crafted malicious HTTP code, an attacker can cause ICQ to hang and consume 100% CPU usage, launching a DoS attack.
6. ICQ's GIF parsing/display library has an input validation flaw:
ICQ's dedicated graphics parsing/display library (created in “icqateimg32.dll”) has a flaw when parsing incoming GIF89a headers, which can trigger a DoS attack.
Solution:
At present the vendor has not released a patch for this flaw. Users should keep an eye on the vendor's site: http://www.icq.com/
Release date: 2003-5-8
Affected program: ICQ Pro 2003a and earlier versions
Detailed description:
Mirabilis ICQ is a very popular instant messaging program, with functions such as chatting, sending email, SMS, and wireless pager messages. ICQ has six flaws that can cause users to be unable to use ICQ normally, and allow attackers to execute arbitrary code on the target user's system:
1. POP3 Client format string flaw:
ICQ's POP3 client has a format string flaw in the UIDL command server response, which can allow an attacker to impersonate a POP3 server.
2. POP3 Client “Subject” buffer overflow flaw:
ICQ's POP3 client has a buffer overflow flaw when processing the “Subject” field of an EMAIL header. This flaw is triggered if the EMAIL subject contains more than 16 bits of characters. By sending a carefully crafted malicious EMAIL subject to the target user, an attacker can execute arbitrary commands on the target user's machine.
3. POP3 Client “Date” buffer overflow flaw:
ICQ's POP3 client has a buffer overflow flaw when processing the “Date” field of an EMAIL header. This flaw is triggered if the EMAIL subject contains more than 16 bits of characters. By sending a carefully crafted malicious EMAIL subject to the target user, an attacker can execute arbitrary commands on the target user's machine.
4. ICQ “Features on Demand” spoofing attack:
ICQ can auto-upgrade by calling the “ICQ Features on Demand” function. Because the program lacks proper authentication and uses hard-coded information, an attacker can use spoofing methods to install malicious programs on the target user's machine and execute arbitrary code.
5. Message announcement DoS attack:
The dedicated HTTP parsing/display library ICQ uses to display message announcements in the message window has a flaw when parsing tag input. By impersonating a static ADS server and sending carefully crafted malicious HTTP code, an attacker can cause ICQ to hang and consume 100% CPU usage, launching a DoS attack.
6. ICQ's GIF parsing/display library has an input validation flaw:
ICQ's dedicated graphics parsing/display library (created in “icqateimg32.dll”) has a flaw when parsing incoming GIF89a headers, which can trigger a DoS attack.
Solution:
At present the vendor has not released a patch for this flaw. Users should keep an eye on the vendor's site: http://www.icq.com/
C++C++C++C++C++C++C++C++C++C++C++C++C++C++C++
C++ ☆☆☆ 中国DOS联盟成员 ☆☆☆ C++
C++ ★★★ 爱提问的红色狂想 ★★★ C++
C++C++C++C++C++C++C++C++C++C++C++C++C++C++C++
C++ ☆☆☆ 中国DOS联盟成员 ☆☆☆ C++
C++ ★★★ 爱提问的红色狂想 ★★★ C++
C++C++C++C++C++C++C++C++C++C++C++C++C++C++C++

