CVE-2001-0233

micq < 0.4.6 - Buffer Overflow via Long Description Field

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2001-0233. PoCs published by tHE rECIdjVO.

AI-analyzed exploit summary This exploit targets a remote buffer overflow in micq-0.4.6, allowing arbitrary code execution via a crafted UDP packet. It includes shellcode to spawn a bind shell on port 10105.

Description

Buffer overflow in micq client 0.4.6 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Description field.

Exploits (1)

exploitdb WORKING POC VERIFIED
by tHE rECIdjVO · cremotelinux
https://www.exploit-db.com/exploits/20569

This exploit targets a remote buffer overflow in micq-0.4.6, allowing arbitrary code execution via a crafted UDP packet. It includes shellcode to spawn a bind shell on port 10105.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: micq-0.4.6
No auth needed
Prerequisites: Network access to the target · Knowledge of the ICQ session ID
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Patch vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2001-005.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/5962
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2001-01/0307.html
Patch, Vendor Advisory vendor-advisory x_refsource_freebsd
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:14.micq.asc
Patch, Vendor Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2001/dsa-012
Patch, Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2001-01/0395.html

Scores

EPSS 0.1455
EPSS Percentile 96.2%

Details

Status published
Products (6)
debian/debian_linux 2.2
matthew_smith/micq < 0.4.6
redhat/linux 6.0
redhat/linux 6.1
redhat/linux 6.2
redhat/linux 7.0
Published Mar 26, 2001
Tracked Since Feb 18, 2026