PT-2001-1061 · Licq · Licq

Published

2001-02-28

·

Updated

2017-10-10

·

CVE-2001-0440

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions licq versions 1.0.2 and earlier licq version 1.0.2
Description The issue concerns multiple vulnerabilities in the licq package that can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. A buffer overflow in logging functions allows remote attackers to cause a denial of service and possibly execute arbitrary commands.
Recommendations For licq versions 1.0.2 and earlier, update to version 1.0.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the logging functions until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-08155
CVE-2001-0440

Affected Products

Licq