Back to Database
Status published
High
CVE-2001-0439
licq before 1.0.3 allows remote attackers to execute arbitrary commands...
Vulnerability Description
licq before 1.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2001-0439
Credits & Attribution
No credits recorded in the NVD database.
References
- http://archives.neohapsis.com/archives/freebsd/2001-04/0607.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6261
- http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-032.php3
- http://www.redhat.com/support/errata/RHSA-2001-023.html
- http://www.osvdb.org/5641
- http://www.redhat.com/support/errata/RHSA-2001-022.html
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000389
More from licq
View All →CVE-2008-1996
licq before 1.3.6 allows remote attackers to cause a denial...
Medium
5
CVE-2003-0363
Format string vulnerability in LICQ 1.2.6, 1.0.3 and possibly other...
High
7.5
CVE-2002-0251
Buffer overflow in licq 1.0.4 and earlier allows remote attackers...
High
7.5
CVE-2001-0440
Buffer overflow in logging functions of licq before 1.0.3 allows...
High
7.5
Affected Vendor
licq
View all reports →Affected Software
licq, linux, freebsd, mandrake linux, mandrake linux corporate server
Vulnerable Versions:
0, 4.0, 4.0es, 4.1, 4.2, 5.0, 3.5.1, 7.1, 7.2, 1.0.1, 7.0
Timeline
Official Publish:
September 18th, 2001
Last Modified:
August 8th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.