J-Security Center

Title: Mirabilis ICQ Sound Scheme Remote Configuration Modification Vulnerability

Severity: MODERATE

Description:

ICQ is an instant messenger client for Microsoft Windows systems. ICQ includes support for sound schemes. ICQ sound scheme files are generally given the .scm extension.

It is possible for a remote user to make some modifications to the configuration of some versions of ICQ. Reportedly, it is possible to modify sounds by forcing a vulnerable user to access a .scm file. This may be accomplished by sending the vulnerable user an HTML formatted email or enticing the user into viewing a malicious HTML page.

The HTML content must reference an available .scm file within an IFRAME tag. If the HTML is then viewed, the sound scheme will be automatically loaded, modifying the ICQ configuration.

It is not currently known if any other ICQ configuration settings can be modified in this fashion.

Affected Products:

  • Mirabilis ICQ 2002 0.0.0a Build#3722
  • Mirabilis ICQ 2002 0.0.0a Build#3727

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.