PT-2006-1815 · Icq+1 · Icqlite+2
Published
2006-02-18
·
Updated
2018-10-19
·
CVE-2006-0766
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ICQ versions 2003a through 2003b
ICQ Lite versions 4.0 through 4.1
Description
The issue allows remote attackers to hide malicious file extensions and bypass Windows security warnings by using a filename that ends in an assumed-safe extension, potentially tricking a user into executing arbitrary programs. This could be achieved by modifying properties such as company name, icon, and description.
Recommendations
For ICQ versions 2003a and 2003b, consider avoiding the use of filenames with assumed-safe extensions until a fix is available.
For ICQ Lite versions 4.0 and 4.1, restrict the execution of files received from untrusted sources to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Icq
Icqlite
Windows