Overview
The Protocol Analysis Module (PAM) used by Internet Security Systems (ISS) intrusion detection and prevention products does not properly handle ICQ server response messages. An unauthenticated, remote attacker could execute arbitrary code by sending a specially crafted UDP packet.
Description
ISS intrusion detection and prevention products include a component that performs application layer inspection of the ICQ protocol. From the ISS Alert: The Protocol Analysis Module (PAM) facilitates the parsing of network protocols in order to perform further analysis and attack detection. ICQ is a popular instant messaging application developed by ICQ Inc., a subsidiary of America Online. In order to detect attacks targeting instant messaging software, PAM parses several IM protocols including ICQ. |
Impact
An unauthenticated, remote attacker could execute arbitrary code with the privileges of the process running the PAM. RealSecure and BlackICE products run on Microsoft Windows platforms with SYSTEM privileges. |
Solution
Upgrade |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.eeye.com/html/Research/Upcoming/20040308.html
- http://www.eeye.com/html/Research/Advisories/AD20040318.html
- http://xforce.iss.net/xforce/alerts/id/166
- http://xforce.iss.net/xforce/alerts/id/167
- http://www.iss.net/download/
- http://secunia.com/advisories/11073/
- http://www.securityfocus.com/bid/9913
- http://www.caida.org/research/security/witty/
Acknowledgements
This vulnerability was reported by eEye Digital Security.
This document was written by Art Manion and Jason A. Rafail.
Other Information
CVE IDs: | CVE-2004-0362 |
Severity Metric: | 30.44 |
Date Public: | 2004-03-08 |
Date First Published: | 2004-03-20 |
Date Last Updated: | 2009-06-12 21:38 UTC |
Document Revision: | 42 |