PT-2003-1455 · Mirabilis · Mirabilis Icq Pro
Daniel Benmergui
+3
·
Published
2003-05-07
·
Updated
2017-07-11
·
CVE-2003-0238
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
Mirabilis ICQ Pro version 2003a
Description:
The issue allows remote attackers to cause a denial of service by consuming CPU resources. This is achieved by spoofing the address of an ADS server and sending HTML with a -1 width in a table tag.
Recommendations:
For Mirabilis ICQ Pro version 2003a, consider disabling the rendering of HTML tables with invalid width parameters as a temporary workaround until a patch is available. Restrict access to the Message Session window to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mirabilis Icq Pro