• About Us
  • Search
  • Compatibility
  • Forums
  • Archive
  • Channels
  • Home
To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.
Warp2Search.net » News » May 2003 » Multiple Vulnerabilities in Mirabilis ICQ Client !

Multiple Vulnerabilities in Mirabilis ICQ Client !

Posted by: [NT] on: 05/06/2003 02:07 PM [ Print | 0 comment(s) ] · 2291 views

Mirabilis ICQ client is a popular program that enables users to communicate through instant messaging, chat, sending emails, SMS and wireless-pager messages, as well as transfering files and URLs.

Six security vulnerabilities were found that could lead to various forms of exploitation ranging from denying users the ability to use ICQ services to execution of arbitrary commands on vulnerable systems.
Following client is been affected: Mirabilis ICQ Pro 2003a and previous versions.
The following vulnerabilities were found: Read More



[BID 7461, CAN-2003-0235, VU#936164] POP3 Client Format String in UIDL Field: ICQ provides an integrated POP3 client vulnerable to a format string attack in the UIDL command server response string (the unique-id of a message). This vulnerability can be successfully exploited by an attacker able to impersonate the POP3 server.

[BID 7462, CAN-2003-0236, VU#792988] "Subject" signed overflow in POP3 Client: ICQ provides an integrated POP3 client vulnerable to a 16bit sign overflow in the "Subject" field of e-mail headers. An attacker may be able to execute arbitrary commands by sending a malformed e-mail header to a vulnerable client.

[BID 7463, CAN-2003-0236, VU#829860] "Date" signed overflow in POP3 Client: ICQ provides an integrated POP3 client vulnerable to a 16bit sign overflow in the "Date" field of e-mail headers. An attacker may be able to execute arbitrary commands by sending a malformed e-mail header to a vulnerable client.

[BID 7465, CAN-2003-0238, VU#967316] Message advertisements denial of service attack: ICQ displays advertisements inside a message window (called 'Message Session') by using a proprietary HTML parsing/rendering library vulnerable to malformed tags input. By impersonating the static ADS server, an attacker may send malformed HTML code to the ADS rendering window freezing the ICQ interface and using 100% CPU.

[BID 7466, CAN-2003-0239, VU#680788] Input validation error in ICQ's GIF parsing/rendering library: ICQ implements its own image parsing/rendering library (found in 'icqateimg32.dll') vulnerable to an input validation error, causing a denial of service. The problem is triggered while parsing GIF89a headers.

Mirabilis is allready informed but a fix/ fixed version has not been released yet.

Get more informations over @ CoreSecurity


Digg it! Del.icio.us Technorati Furl Google Bookmarks

« Athlon MP 2800+ Released · Multiple Vulnerabilities in Mirabilis ICQ Client ! · EluminiX Illuminated Keyboard Review »

Warp2Search.net » News » May 2003 » Multiple Vulnerabilities in Mirabilis ICQ Client !

Latest News

· Opera 10.10 Final
· NZXT Guardian 921 PC Case Review
· ATI Catalyst 9.11 Windows 7 Driver Analysis
· NZXT M59 Mid-Tower Computer Case Review
· Opera (BETA) 10.10 (Build 1893)
· GMER 1.0.15.15252
· Windows Home Server Power Pack 3: November 24
· MemSet 4.1
· SetFSB 2.2.134.98
· ProduKey 1.40
· Hiren's BootCD 10.1
· FinalBurner Free 2.15.0.171
· Replay Music 3.92
· Google Chrome BETA 4.0.249.4
· Sapphire 5970 Cfx and HIS 5970 CFx Review
· Ultra X4 500 W Power Supply Review
· PC Tools ThreatFire 4.7.0.9
· ZipGenius 6.2.0.2000

Community Forum

· S.T.A.L.K.E.R.: Call of Pripyat Benchmark
Posted by Regeneration

· Thermaltake BlacX Duet Dual Hard Drive Docking Station Review @ Tweaknews
Posted by Tweaknews

· Noctua NH-D14 Premium CPU Cooler Review @ Clunk.org.uk
Posted by Clunk

· HIS Radeon HD4850 iCooler 1GB Videocard Review @ Tweaknews
Posted by Tweaknews

· Building An Ultimate Gaming Machine!
Posted by ezone


Nodes To Friends





Online Users

There are currently 477 user(s) online:
Ask Jeeves, Cuil, Google, Live Search, MSN, Yahoo

© 2007-2009 Esselbach Internet Solutions
All products mentioned are registered trademarks or trademarks of their respective owners.
Read our disclaimer over here and our Privacy Policy over here
Managed with Contentteller(R) Business Edition, (C) 2002 - 2009 Esselbach Internet Solutions