PT-2003-1453 · Mirabilis · Mirabilis Icq Pro

Daniel Benmergui

+3

·

Published

2003-05-07

·

Updated

2017-07-11

·

CVE-2003-0236

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Mirabilis ICQ Pro version 2003a
Description: The issue is related to integer signedness errors in the POP3 client, which can be exploited by remote attackers to execute arbitrary code. This can be achieved via the Subject or Date headers.
Recommendations: For Mirabilis ICQ Pro version 2003a, consider disabling the POP3 client functionality until a patch is available to prevent potential exploitation. Restrict access to the POP3 client to minimize the risk of arbitrary code execution.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0236

Affected Products

Mirabilis Icq Pro