PT-2001-1061 · Licq · Licq
Published
2001-02-28
·
Updated
2017-10-10
·
CVE-2001-0440
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
licq versions 1.0.2 and earlier
licq version 1.0.2
Description
The issue concerns multiple vulnerabilities in the licq package that can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. A buffer overflow in logging functions allows remote attackers to cause a denial of service and possibly execute arbitrary commands.
Recommendations
For licq versions 1.0.2 and earlier, update to version 1.0.3 or later to resolve the issue.
As a temporary workaround, consider restricting access to the logging functions until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Licq