Stack-based buffer overflow in the LiveJournal support (hooks/ljhook.cc) in CenterICQ 4.9.11 through 4.21.0, when using unofficial LiveJournal servers, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by adding the victim as a friend and using long (1) username and (2) real name strings.
2007-01-10T00:28:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | centericq | centericq | 4.9.11 | Yes |
| Application | centericq | centericq | 4.9.12 | Yes |
| Application | centericq | centericq | 4.12 | Yes |
| Application | centericq | centericq | 4.13 | Yes |
| Application | centericq | centericq | 4.14 | Yes |
| Application | centericq | centericq | 4.20 | Yes |
| Application | centericq | centericq | 4.21 | Yes |