First published: Tue Nov 07 2006(Updated: )
The ICQPhone.SipxPhoneManager ActiveX control in America Online ICQ 5.1 allows remote attackers to download and execute arbitrary code via the DownloadAgent function, as demonstrated using an ICQ avatar.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ICQ | =5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5650 is considered a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2006-5650, users should update to a newer version of America Online ICQ that addresses this vulnerability.
The impact of CVE-2006-5650 includes the possibility for attackers to download and execute arbitrary code on the affected system.
CVE-2006-5650 affects AOL ICQ version 5.1.
Yes, CVE-2006-5650 can be exploited via the DownloadAgent function using an ICQ avatar.