ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

ICQ flaws open PCs to attack

Published: 06 May 2003 07:21 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Two serious flaws in America Online's ICQ software could allow an online attacker to take control of a person's PC, a Boston security firm warned in an advisory released on Monday.

Core Security Technologies described the vulnerabilities in an advisory released to several public security lists. While the company found a total of six flaws, it said only two have serious implications because they could allow an attacker to run code on the victim's computer.

"However, the risk associated to each vulnerabilities is highly dependent on the environment in which ICQ is being used," said Ivan Arce, chief technology officer for Core. "Generally we don't make assumptions about risk in our advisories because we don't think the one-size-fits-all approach is valid."

The vulnerable ICQ Pro 2003a client is the latest version of America Online's ICQ instant messaging software, which has been downloaded from CNET Network's Download.com site more than 228 million times. Last year, the company offered a slimmed-down version called ICQ Lite. That application doesn't have the flaws, according to the advisory.

No one from America Online's ICQ subsidiary was available on Monday to comment on the alleged flaws. The security researchers also noted that they had problems reaching those responsible for security at ICQ.

"We also attempted to get specific security contact points from third parties that might have reported ICQ bugs before but had no success with this either, so after over a month of going back and forth with the advisory we finally decided to publish it unilaterally," he said.

Three of the vulnerabilities, including one of the critical flaws, occurred in the software's email feature. A bug in the component could allow an attacker to use the way the software handles email to cause it to execute code, if the attacker can impersonate the user's email server.

The other so-called critical vulnerability appeared in a feature of ICQ that allows automated updating, the group said. Because that component doesn't have adequate security, an attacker could pretend to be sending a legitimate update when in reality the upgrade is hostile code.

Israeli company Mirabilis, which created the software, was bought by America Online in June 1998 and its name was changed to ICQ Inc. ICQ is short for "I Seek You."


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
46 out of 93 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Database Developers ( SQL / T-SQL / SSIS / ETL ) - Chatham Maritime

Work with Third Parties to deploy changes to data structures and content. Take business analyst code written in SAS or T-SQL and create automated SQL ...

Automated tester

Skills Data driven test automation using Java within Websphere Java 1.4 Knowledge of Databases Oracle, DB2 preferably XML Preparation of automated ...

Business Analyst Cash Equities Trading Operations London City

Leading City Investment Bank seek the talents of a Business Analyst to assist in a large integration programme. This should include extensive ...

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains