Vulnerability Development mailing list archives

Re: icq vuln


From: marcolof () WAM UMD EDU (Rietveld, Marco)
Date: Sun, 16 Jan 2000 12:07:39 -0500


|2000-01-14-13:20:27 nascheme:
|> ICQ is a disaster waiting to happen.  There is strcat and strcpy
|> all over the place last time I looked at it.  I didn't have time
|> to develop and exploit though.

there was a recent post in bugtraq about how there's a buffer-overflow
vulnerability when messaging URL's.. it's explained at
http://www.securityfocus.com/vdb/.. the vulnerabilities database..

marcolof


Current thread: