CVE-2002-1362
published 2002-12-23CVE-2002-1362: mICQ 0.4.9 and earlier allows remote attackers to cause a denial of service (crash) via malformed ICQ message types without a 0xFE separator character.
PriorityP413medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.67%
74.2th percentile
mICQ 0.4.9 and earlier allows remote attackers to cause a denial of service (crash) via malformed ICQ message types without a 0xFE separator character.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| matthew_smith | micq | — | — |
| matthew_smith | micq | — | — |
| matthew_smith | micq | — | — |
| matthew_smith | micq | — | — |
| matthew_smith | micq | — | — |
| matthew_smith | micq | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xmv7-rrcx-3gfq: mICQ 0
ghsa_unreviewed·2022-04-30
CVE-2002-1362 [MEDIUM] GHSA-xmv7-rrcx-3gfq: mICQ 0
mICQ 0.4.9 and earlier allows remote attackers to cause a denial of service (crash) via malformed ICQ message types without a 0xFE separator character.
Red Hat
security flaw
vendor_redhat·2002-11-03·CVSS 5.0
CVE-2002-1362 [MEDIUM] security flaw
security flaw
mICQ 0.4.9 and earlier allows remote attackers to cause a denial of service (crash) via malformed ICQ message types without a 0xFE separator character.
No detection rules found.
No public exploits indexed.
CWE
Improper Handling of Missing Special Element
mitre_cwe
CWE-166 Improper Handling of Missing Special Element
CWE-166: Improper Handling of Missing Special Element
The product receives input from an upstream component, but it does not handle or incorrectly handles when an expected special element is missing.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Availability. Impact: DoS: Crash, Exit, or Restart.
Potential Mitigations:
Developers should anticipate that special elements will be removed in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system.
[Implementation] Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that
CWE
Improper Handling of Invalid Use of Special Elements
mitre_cwe
CWE-159 Improper Handling of Invalid Use of Special Elements
CWE-159: Improper Handling of Invalid Use of Special Elements
The product does not properly filter, remove, quote, or otherwise manage the invalid use of special elements in user-controlled input, which could cause adverse effect on its behavior and integrity.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Integrity. Impact: Unexpected State.
Potential Mitigations:
Developers should anticipate that special elements will be injected/removed/manipulated in the input vectors of their software system. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system.
[Implementation] Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of accep
http://www.debian.org/security/2002/dsa-211http://www.redhat.com/support/errata/RHSA-2003-118.htmlhttp://www.securityfocus.com/bid/6392https://exchange.xforce.ibmcloud.com/vulnerabilities/10872http://www.debian.org/security/2002/dsa-211http://www.redhat.com/support/errata/RHSA-2003-118.htmlhttp://www.securityfocus.com/bid/6392https://exchange.xforce.ibmcloud.com/vulnerabilities/10872
2002-12-23
Published