Bugtraq: Re: licq remote DoS?
Re: licq remote DoS?
Related Files:
FreeBSD Security Advisory FreeBSD-SA-01:35.licq - The licq port, versions prior to 1.0.3, contains a vulnerability in URL parsing. URLs received by the licq program are passed to the web browser using the system() function. Since licq performs no sanity checking, a remote attacker will be able to pipe commands contained in the URL causing the client to execute arbitrary commands. Homepage: http://www.freebsd.org/security.
LICQ and Gnome-ICQ contain remote denial of service vulnerabilities when users send .rtf files. Tested from NT4 and NT5 workstations (running ICQ 2000b) to various Linux distro’s. Authored By The Exploiters
Simple Denial of Service attack against LICQ (Linux ICQ clone). Thanks for the heads-up, Spikey.
Bugtraq Security Systems Security Advisory - Multiple vulnerabilities have been discovered in the Applied Watch Command Center IDS. Two exploits have been released to demonstrate these flaws. The first, appliedsnatch.c, allows a remote attacker to add a user to the console without having to authenticate to the system. The second, addrule.c, allows a remote attacker to add custom IDS alerts to all sensor nodes in a network, enabling a human denial-of-service attack by making good packets look bad. Related CVE Numbers: CAN-2003-0970, CAN-2003-0971. Homepage: http://www.bugtraq.org. Authored By The Bugtraq Team
Really Simple PHP and Ajax, or RSPA, is susceptible to a remote file inclusion vulnerability. Version RSPA-2007-03-23 is susceptible. Homepage: http://www.bugtraq.ir/. Authored By Hamid Ebadi
Complete archive of the excellent threads recently posted on the BugTraq mailing list regarding Intrusion Detection Systems. IDS theories, implementations, problems, and reviews of commercial products are among the topics covered.
Red Hat Security Advisory RHSA-2001:022-03 - licq as shipped with Red Hat Linux 7 is vulnerable to two security problems: An overrunnable buffer in its logging code, and an unguarded system() call to execute an external browser when receiving an URL. Homepage: http://www.redhat.com/support/errata/rh7-errata-security.html.
ZPanel suffers from a remote file inclusion vulnerability. Homepage: http://www.bugtraq.ir/. Authored By Hamid Ebadi
Acubix PicoZip version 4.02 suffers from a directory traversal vulnerability. Homepage: http://www.bugtraq.ir/. Authored By Hamid Ebadi
T1Lib suffers from a buffer overflow vulnerability. Homepage: http://www.bugtraq.ir/. Authored By Hamid Ebadi