![]() |
China DOS Union-- Unite DOS · Advance DOS · Grow DOS --Union site: www.cn-dos.net Forum site: www.cn-dos.net/forum |
| Guest | Log in | Register | Members | Search | China DOS Union |
|
中国DOS联盟论坛 The time now is 2026-08-25 18:33 |
47,812 topics / 349,910 posts / today 0 new / 48,263 members |
| 其它操作系统综合讨论区 » [Repost] Mirabilis ICQ instant messaging program has six major flaws |
| Printable Version 1,397 / 0 |
| Floor1 红色狂想 | Posted 2003-05-09 00:00 |
| 金牌会员 Posts 1,501 Credits 4,289 From 河南省 | |
|
Software flaws & virus bulletin:
Release date: 2003-5-8 Affected program: ICQ Pro 2003a and earlier versions Detailed description: Mirabilis ICQ is a very popular instant messaging program, with functions such as chatting, sending email, SMS, and wireless pager messages. ICQ has six flaws that can cause users to be unable to use ICQ normally, and allow attackers to execute arbitrary code on the target user's system: 1. POP3 Client format string flaw: ICQ's POP3 client has a format string flaw in the UIDL command server response, which can allow an attacker to impersonate a POP3 server. 2. POP3 Client “Subject” buffer overflow flaw: ICQ's POP3 client has a buffer overflow flaw when processing the “Subject” field of an EMAIL header. This flaw is triggered if the EMAIL subject contains more than 16 bits of characters. By sending a carefully crafted malicious EMAIL subject to the target user, an attacker can execute arbitrary commands on the target user's machine. 3. POP3 Client “Date” buffer overflow flaw: ICQ's POP3 client has a buffer overflow flaw when processing the “Date” field of an EMAIL header. This flaw is triggered if the EMAIL subject contains more than 16 bits of characters. By sending a carefully crafted malicious EMAIL subject to the target user, an attacker can execute arbitrary commands on the target user's machine. 4. ICQ “Features on Demand” spoofing attack: ICQ can auto-upgrade by calling the “ICQ Features on Demand” function. Because the program lacks proper authentication and uses hard-coded information, an attacker can use spoofing methods to install malicious programs on the target user's machine and execute arbitrary code. 5. Message announcement DoS attack: The dedicated HTTP parsing/display library ICQ uses to display message announcements in the message window has a flaw when parsing tag input. By impersonating a static ADS server and sending carefully crafted malicious HTTP code, an attacker can cause ICQ to hang and consume 100% CPU usage, launching a DoS attack. 6. ICQ's GIF parsing/display library has an input validation flaw: ICQ's dedicated graphics parsing/display library (created in “icqateimg32.dll”) has a flaw when parsing incoming GIF89a headers, which can trigger a DoS attack. Solution: At present the vendor has not released a patch for this flaw. Users should keep an eye on the vendor's site: http://www.icq.com/ |
|
|
[ Contact the Union admin team -
中国DOS联盟 -
Standard version ] Sponsored by ifanr Inc | © 2001–2023 |