J-Security Center

Title: QIP 2005 Malformed Rich Text Message Remote Denial of Service Vulnerability

Severity: MODERATE

Description:

QIP 2005 is an instant-messaging client for the ICQ protocol; it is available for Microsoft Windows.

QIP 2005 is prone to a denial-of-service vulnerability because it fails to handle malformed messages. A remote attacker may exploit this issue by sending a maliciously constructed Rich Text Format message to the vulnerable client.

Exploiting this issue may allow attackers to cause the application to hang and consume excessive computer resources, denying service to legitimate users.

NOTE: This issue may occur in a third-party component used by QIP 2005, but this has not been confirmed.

This issue affects QIP 2005 build 8082; other versions may also be vulnerable.

Affected Products:

  • QIP QIP 2005 build 8082

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.