CyberInsecure.com

Daily cyber threats and internet security news: network security, online safety and latest security alerts
April 22nd, 2008

ICQ 6 Personal Status Processing Vulnerability

A new vulnerability in ICQ can be exploited by malicious people to compromise another user’s system. The vulnerability is caused due to a boundary error when processing “Personal Statuses” set via the “Personal Status Manager” menu. This can be exploited to cause a heap-based buffer overflow by creating a specially crafted personal status and e.g. sending a message to another user.

Successful exploitation allows execution of arbitrary code.

The vulnerability is reported in version 6 build 6043. Other versions may also be affected.

The vendor has reportedly issued a fix via automatic updates.

Share this item with others:

More on CyberInsecure:
  • ICQ Ads Infect Users With Scareware Via Malvertizing
  • Unpatched Yahoo! Messenger Flaw Allows Status Updates Remote Hijacking
  • Critical PDF Processing Vulnerability In BlackBerry Enterprise Server
  • Ukrainian Scammers Will Hack Any Facebook, Myspace, ICQ Account For Just 100USD
  • Twitter Bug Allowed Users To Forcefully Add Followers

  • If you found this information useful, consider linking to it from your own website.
    Just copy and paste the code below into your website (Ctrl+C to copy)
    It will look like this: ICQ 6 Personal Status Processing Vulnerability

    Leave a Reply

    Comments with unsolicited links to other resources will be marked as spam. DO NOT leave links in comments. Please leave your real email, it wont be published.

    *
    To prove you’re a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.