ICQ flaws open PCs to attack

All of us accessing this forum are using a computer, if you've got a problem, have or need information, then post here.


Reply
 
LinkBack Thread Tools Display Modes
Old 07-05-2003   #1
net1
Guest
 
Posts: n/a
ICQ flaws open PCs to attack

A security company has released an advisory detailing six flaws in the ICQ communication software, two of which are serious vulnerabilities
Two serious flaws in America Online's ICQ software could allow an online attacker to take control of a person's PC, a Boston security firm warned in an advisory released on Monday.

Core Security Technologies described the vulnerabilities in an advisory released to several public security lists. While the company found a total of six flaws, it said only two have serious implications because they could allow an attacker to run code on the victim's computer.

"However, the risk associated to each vulnerabilities is highly dependent on the environment in which ICQ is being used," said Ivan Arce, chief technology officer for Core. "Generally we don't make assumptions about risk in our advisories because we don't think the one-size-fits-all approach is valid."

The vulnerable ICQ Pro 2003a client is the latest version of America Online's ICQ instant messaging software, which has been downloaded from CNET Network's Download.com site more than 228 million times. Last year, the company offered a slimmed-down version called ICQ Lite. That application doesn't have the flaws, according to the advisory.

No one from America Online's ICQ subsidiary was available on Monday to comment on the alleged flaws. The security researchers also noted that they had problems reaching those responsible for security at ICQ.

"We also attempted to get specific security contact points from third parties that might have reported ICQ bugs before but had no success with this either, so after over a month of going back and forth with the advisory we finally decided to publish it unilaterally," he said.

Three of the vulnerabilities, including one of the critical flaws, occurred in the software's email feature. A bug in the component could allow an attacker to use the way the software handles email to cause it to execute code, if the attacker can impersonate the user's email server.

The other so-called critical vulnerability appeared in a feature of ICQ that allows automated updating, the group said. Because that component doesn't have adequate security, an attacker could pretend to be sending a legitimate update when in reality the upgrade is hostile code.

Israeli company Mirabilis, which created the software, was bought by America Online in June 1998 and its name was changed to ICQ Inc. ICQ is short for "I Seek You."
  Reply With Quote
Reply

Bookmarks

Tags
attack, flaws, icq, open, pcs


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
can @metabox open freeXtv poliat Receiver software, international Section 7 09-06-2004 09:43 AM
Hardcore Channels open by Matrix Reloaded user909090 Adult satellite channels 2 23-01-2004 09:28 PM
DirectX attack expected net1 Computer Discussion 0 23-08-2003 09:41 PM
BBC counters Ball's licence fee attack net1 Daily Satellite and Broadcast industry News 0 22-08-2003 10:22 PM
BSkyB chief launches attack on licence fee net1 Daily Satellite and Broadcast industry News 0 22-08-2003 07:39 PM






All times are GMT +1. The time now is 01:30 AM.


All views and information expressed in users' communications and profiles represent the opinions of the users concerned and do not represent the views of Satellites.co.uk. All images and news content are believed to be in the public domain, except where otherwise stated. Forum software by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.

Content Relevant URLs by vBSEO 3.3.1