Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

LICQ Format String Denial Of Service Vulnerability

LICQ is a freely available, open-source ICQ client for variants of Unix and Linux operating systems.

LICQ is prone to denial of service attacks. Excessively long requests containing format strings such as %d will cause the client to crash. The LICQ crashes when sent 1024+ bytes.

Due to the nature of this issue, it may be possible to leverage this vulnerability to cause arbitrary attacker-supplied instructions to be executed on a host running the vulnerable software. Though this possibility has not been confirmed.







 

Privacy Statement
Copyright 2009, SecurityFocus