First published: Mon Dec 23 2002(Updated: )
mICQ 0.4.9 and earlier allows remote attackers to cause a denial of service (crash) via malformed ICQ message types without a 0xFE separator character.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Matthew Smith micq | =0.4.3 | |
Matthew Smith micq | =0.4.6 | |
Matthew Smith micq | =0.4.9 | |
Matthew Smith micq | =0.4.9.2b | |
Matthew Smith micq | =0.4.9.3 | |
Matthew Smith micq | =0.4.9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1362 is considered a denial of service vulnerability that can lead to application crashes.
To fix CVE-2002-1362, upgrade mICQ to version 0.4.10 or later where the vulnerability is patched.
Versions 0.4.3, 0.4.6, 0.4.9, 0.4.9.2b, 0.4.9.3, and 0.4.9.4 of mICQ are all affected by CVE-2002-1362.
Yes, CVE-2002-1362 can be exploited remotely through the sending of malformed ICQ message types.
CVE-2002-1362 can lead to a denial of service that disrupts the normal functionality of the mICQ application.