33851Third-party advisory
http://secunia.com/advisories/33851 CVE-2009-0769
QIP 2005 - Malformed Rich Text Message Remote Denial of Service
Record summary
CVE-2009-0769 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
QIP 2005 build 8082 allows remote attackers to cause a denial of service (CPU consumption and application hang) via a crafted Rich Text Format (RTF) ICQ message, as demonstrated by an {\rtf\pict\&&} message. NOTE: the vulnerability may be in Sergey Tkachenko TRichView. If so, then this should not be treated as a vulnerability in QIP.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBQIP 2005 - Malformed Rich Text Message Remote Denial of ServiceExploitDB exploitby ShineShadowNot analyzed1 file
References
551755vdb entry
http://www.osvdb.org/51755 20090204 QIP 2005 Denial of Service Vulnerabilitymailing list
http://www.securityfocus.com/archive/1/500656/100/0/threaded 33609vdb entry
http://www.securityfocus.com/bid/33609 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-0769