Discovered a critical vulnerability in the popular manager, send instant messages to ICQ 6. An unspecified error when processing messages containing format string characters. Successful exploitation of this vulnerability, an attacker need only send the user a specially crafted message that could be opened in the pop-up preview window or in the main window of the client.
Example of a message that causes a denial of service ICQ client:.
'0000000s'.
Vulnerabilities in IM clients are not news to anyone, but at the same time pose a serious threat to the security. In 2007 it was published 16 vulnerabilities in instant messaging managers, five of which (in Trillian, MSN Messenger, Miranda and Skype) allow execution of arbitrary code.
Ways to address the vulnerability does not exist at the present time. SecurityLab recommends that all users not to use a vulnerable version of the patch before the release of ICQ.
stfw. ru.
Комментариев нет:
Отправить комментарий