PT-2003-1455 · Mirabilis · Mirabilis Icq Pro

Daniel Benmergui

+3

·

Published

2003-05-07

·

Updated

2017-07-11

·

CVE-2003-0238

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: Mirabilis ICQ Pro version 2003a
Description: The issue allows remote attackers to cause a denial of service by consuming CPU resources. This is achieved by spoofing the address of an ADS server and sending HTML with a -1 width in a table tag.
Recommendations: For Mirabilis ICQ Pro version 2003a, consider disabling the rendering of HTML tables with invalid width parameters as a temporary workaround until a patch is available. Restrict access to the Message Session window to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0238

Affected Products

Mirabilis Icq Pro