CVE-2006-4662

UnknownEPSS 6.15%

Last modified

CVE-2006-4662 is a vulnerability of currently unknown severity. Heap-based buffer overflow in the MCRegEx__Search function in AOL ICQ Pro 2003b Build 3916 and earlier allows remote attackers to execute arbitrary code via an inconsistent length field of a Message in a 0x2711 Type-Length-Value (TLV) type.. EPSS estimates a 6.15% chance of exploitation in the next 30 days.

Description

Heap-based buffer overflow in the MCRegEx__Search function in AOL ICQ Pro 2003b Build 3916 and earlier allows remote attackers to execute arbitrary code via an inconsistent length field of a Message in a 0x2711 Type-Length-Value (TLV) type.

Metrics

EPSS Probability
6.15%

92.6th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
MirabilisIcq0.99b_1.1.1.1
MirabilisIcq0.99b_v.3.19
MirabilisIcq98.0a
MirabilisIcq99a_2.15build1701
MirabilisIcq99a_2.21build1800
MirabilisIcq2000.0a
MirabilisIcq2000.0b_build3278
MirabilisIcq2001a
MirabilisIcq2001b_build3636
MirabilisIcq2001b_build3638
MirabilisIcq2001b_build3659
MirabilisIcq2002a_build3722
MirabilisIcq2002a_build3727
MirabilisIcq2003a
MirabilisIcq2003a_build3777
MirabilisIcq2003a_build3799
MirabilisIcq2003a_build3800
MirabilisIcq2003b
MirabilisIcq2003b_build3096

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2006-4662?
Heap-based buffer overflow in the MCRegEx__Search function in AOL ICQ Pro 2003b Build 3916 and earlier allows remote attackers to execute arbitrary code via an inconsistent length field of a Message in a 0x2711 Type-Length-Value (TLV) type.
How severe is CVE-2006-4662?
Severity scoring for CVE-2006-4662 is pending analysis. The EPSS model estimates a 6.15% probability of exploitation in the next 30 days.
How do I fix CVE-2006-4662?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2006-4662?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST