Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Mirabilis ICQ 98a Vulnerability

A vulnerability exists within the Mirabilis ICQ 98a which allows an attacker to send a file with a malformed name. For example, sending a file to a victim with the name:

"picture.jpg
.exe"

the user receiving the file will only see the "picture.jpg" file and not the ".exe" extension and assume it is a harmless JPG graphic. If they choose to open it automatically with its associated extension (.exe) the file can be executed and an attacker to execute arbitrary code such as a trojan.







 

Privacy Statement
Copyright 2009, SecurityFocus