Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Mirabilis ICQ POP3 Client UIDL Command Format String Vulnerability

Mirabilis ICQ POP3 Client has been reported prone to a format string vulnerability.

It is likely that the problem presents itself due to a programming error in a function used by the POP3 client to handle the unique id of an e-mail message.

Under certain circumstances an attacker may send malicious format string specifiers embedded in the unique id of an e-mail message destined for the ICQ POP3 Client. This may ultimately result in the execution of attacker-supplied code.







 

Privacy Statement
Copyright 2008, SecurityFocus