Bugtraq mailing list archives

Icq 2001&2002 vulnerability


From: Michael <spacoom () gmx net>
Date: 24 Jul 2002 15:38:22 -0000



Icq 2001&2002 have feature, that allows to insert graphical smiles.
I found, that if you send message filled with lots of smiles(icq msg can 
be about 7000 bytes long), then target icq hangs for 10-20 seconds, 
consuming all CPU time, or simply crashs.

It seems for me that such type of message crashs only icq's that have 
large .dat file, which holds all history.

You can download working example from: http://www.iFud.com/dfm/DFMa.exe

As you maybe remember, AOL was trying to threaten me for finding bugs. You 
can find new threats here: http://www.iFud.com/aol.htm

Michael, icq 102166


Current thread: