China DOS Union

-- Unite DOS · Advance DOS · Grow DOS --

Union site: www.cn-dos.net Forum site: www.cn-dos.net/forum
DOS stands for freedom, openness and progress. Let us work hard, learn from the openness and GNU spirit of FreeDOS and Linux, and together build and grow a free GNU GPL world!

中国DOS联盟论坛
The time now is 2026-08-25 17:53
中国DOS联盟论坛 » 其它操作系统综合讨论区 » [Repost] Mirabilis ICQ instant messaging program has six major flaws View 1,396 Replies 0
Original Poster Posted 2003-05-09 00:00 ·  中国 河南 驻马店 联通
金牌会员
★★★★
龙哥DOS
Credits 4,289
Posts 1,501
Joined 2003-02-23 00:00
23-year member
UID 983
Gender Male
From 河南省
Status Offline
Software flaws & virus bulletin:

Release date: 2003-5-8

Affected program: ICQ Pro 2003a and earlier versions

Detailed description:
Mirabilis ICQ is a very popular instant messaging program, with functions such as chatting, sending email, SMS, and wireless pager messages. ICQ has six flaws that can cause users to be unable to use ICQ normally, and allow attackers to execute arbitrary code on the target user's system:
1. POP3 Client format string flaw:
ICQ's POP3 client has a format string flaw in the UIDL command server response, which can allow an attacker to impersonate a POP3 server.
2. POP3 Client “Subject” buffer overflow flaw:
ICQ's POP3 client has a buffer overflow flaw when processing the “Subject” field of an EMAIL header. This flaw is triggered if the EMAIL subject contains more than 16 bits of characters. By sending a carefully crafted malicious EMAIL subject to the target user, an attacker can execute arbitrary commands on the target user's machine.
3. POP3 Client “Date” buffer overflow flaw:
ICQ's POP3 client has a buffer overflow flaw when processing the “Date” field of an EMAIL header. This flaw is triggered if the EMAIL subject contains more than 16 bits of characters. By sending a carefully crafted malicious EMAIL subject to the target user, an attacker can execute arbitrary commands on the target user's machine.
4. ICQ “Features on Demand” spoofing attack:
ICQ can auto-upgrade by calling the “ICQ Features on Demand” function. Because the program lacks proper authentication and uses hard-coded information, an attacker can use spoofing methods to install malicious programs on the target user's machine and execute arbitrary code.
5. Message announcement DoS attack:
The dedicated HTTP parsing/display library ICQ uses to display message announcements in the message window has a flaw when parsing tag input. By impersonating a static ADS server and sending carefully crafted malicious HTTP code, an attacker can cause ICQ to hang and consume 100% CPU usage, launching a DoS attack.
6. ICQ's GIF parsing/display library has an input validation flaw:
ICQ's dedicated graphics parsing/display library (created in “icqateimg32.dll”) has a flaw when parsing incoming GIF89a headers, which can trigger a DoS attack.

Solution:
At present the vendor has not released a patch for this flaw. Users should keep an eye on the vendor's site: http://www.icq.com/

C++C++C++C++C++C++C++C++C++C++C++C++C++C++C++
C++ ☆☆☆ 中国DOS联盟成员 ☆☆☆ C++
C++ ★★★ 爱提问的红色狂想 ★★★ C++
C++C++C++C++C++C++C++C++C++C++C++C++C++C++C++
Forum Jump: