Vulnerabilities > CVE-2001-0440
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 9 | |
OS | 2 | |
Application | 1 |
Exploit-Db
description | LICQ 0.85/1.0.1/1.0.2 Remote Buffer Overflow Vulnerability. CVE-2001-0440 . Remote exploit for unix platform |
id | EDB-ID:20646 |
last seen | 2016-02-02 |
modified | 2000-12-26 |
published | 2000-12-26 |
reporter | Stan Bubrouski |
source | https://www.exploit-db.com/download/20646/ |
title | LICQ 0.85/1.0.1/1.0.2 - Remote Buffer Overflow Vulnerability |
Nessus
NASL family | Mandriva Local Security Checks |
NASL id | MANDRAKE_MDKSA-2001-032.NASL |
description | Versions of Licq prior to 1.0.3 have a vulnerability involving the way Licq parses received URLs. The received URLs are passed to the web browser without any sanity checking by using the system() function. Because of the lack of checks on the URL, remote attackers can pipe other commands with the sent URLs causing the client to unwillingly execute arbitrary commands. The URL parsing code has been fixed in the most recent 1.0.3 version. Users of Linux-Mandrake 7.1 and Corporate Server 1.0.1 will have to manually remove the licq-data package by using |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 61906 |
published | 2012-09-06 |
reporter | This script is Copyright (C) 2012-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/61906 |
title | Mandrake Linux Security Advisory : licq (MDKSA-2001:032-1) |
code |
|
Redhat
advisories |
|
References
- http://archives.neohapsis.com/archives/freebsd/2001-04/0607.html
- http://archives.neohapsis.com/archives/freebsd/2001-04/0607.html
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000389
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000389
- http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-032.php3
- http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-032.php3
- http://www.osvdb.org/5601
- http://www.osvdb.org/5601
- http://www.redhat.com/support/errata/RHSA-2001-022.html
- http://www.redhat.com/support/errata/RHSA-2001-022.html
- http://www.redhat.com/support/errata/RHSA-2001-023.html
- http://www.redhat.com/support/errata/RHSA-2001-023.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6645
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6645