Vulnerability Description
Win32 ICQ 98a 1.30, and possibly other versions, does not display the entire portion of long filenames, which could allow attackers to send an executable file with a long name that contains so many spaces that the .exe extension is not displayed, which could make the user believe that the file is safe to open from the client.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mirabilis | Icq 98A | <= 1.30 |
References
- http://marc.info/?l=bugtraq&m=91522424302962&w=2
- http://www.securityfocus.com/bid/132
- http://marc.info/?l=bugtraq&m=91522424302962&w=2
- http://www.securityfocus.com/bid/132
FAQ
What is CVE-1999-1440?
CVE-1999-1440 is a vulnerability with a CVSS score of 5.1 (MEDIUM). Win32 ICQ 98a 1.30, and possibly other versions, does not display the entire portion of long filenames, which could allow attackers to send an executable file with a long name that contains so many sp...
How severe is CVE-1999-1440?
CVE-1999-1440 has been rated MEDIUM with a CVSS base score of 5.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-1999-1440?
Check the references section above for vendor advisories and patch information. Affected products include: Mirabilis Icq 98A.