ICQ Message Processing Remote Format String Vulnerability
BID:28027
Info
ICQ Message Processing Remote Format String Vulnerability
| Bugtraq ID: | 28027 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1120 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 2008 12:00AM |
| Updated: | Mar 19 2015 09:37AM |
| Credit: | B0B reported this issue. |
| Vulnerable: |
ICQ Inc. ICQ 6 |
| Not Vulnerable: |
ICQ Inc. ICQ 6.0 build 6059 |
Discussion
ICQ Message Processing Remote Format String Vulnerability
ICQ is prone to a remote format-string vulnerability because the application fails to properly sanitize user-supplied input before including it in the format-specifier argument of a formatted-printing function.
A remote attacker may execute arbitrary code in the context of the affected application. Failed exploit attempts will result in a denial of service.
This issue affects ICQ 6 build 6043; other versions may also be vulnerable.
ICQ is prone to a remote format-string vulnerability because the application fails to properly sanitize user-supplied input before including it in the format-specifier argument of a formatted-printing function.
A remote attacker may execute arbitrary code in the context of the affected application. Failed exploit attempts will result in a denial of service.
This issue affects ICQ 6 build 6043; other versions may also be vulnerable.
Exploit / POC
ICQ Message Processing Remote Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
ICQ Message Processing Remote Format String Vulnerability
Solution:
The vendor has addressed this issue in ICQ 6.0 build 6059. Contact the vendor for details.
Solution:
The vendor has addressed this issue in ICQ 6.0 build 6059. Contact the vendor for details.
References
ICQ Message Processing Remote Format String Vulnerability
References:
References:
- ICQ Homepage (Mirabilis)
- ICQ6 User crashen (B0B)