CVE-2006-5650: High severity AOL ICQ vulnerability
Published Nov 7, 2006
·Updated
The ICQPhone.SipxPhoneManager ActiveX control in America Online ICQ 5.1 allows remote attackers to download and execute arbitrary code via the DownloadAgent function, as demonstrated using an ICQ avatar.
Affected Software
1 affected component
AOL ICQ=5.1
Event History
Nov 7, 2006
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:07 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-5650?
CVE-2006-5650 is considered a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2006-5650?
To fix CVE-2006-5650, users should update to a newer version of America Online ICQ that addresses this vulnerability.
3
What is the impact of CVE-2006-5650?
The impact of CVE-2006-5650 includes the possibility for attackers to download and execute arbitrary code on the affected system.
4
Which software is affected by CVE-2006-5650?
CVE-2006-5650 affects AOL ICQ version 5.1.
5
Can CVE-2006-5650 be exploited through an ICQ avatar?
Yes, CVE-2006-5650 can be exploited via the DownloadAgent function using an ICQ avatar.