NeonWizard Posted August 10, 2004 Report Share Posted August 10, 2004 Secunia Advisory: SA12198 Release Date: 2004-08-09 Last Update: 2004-08-10 Highly critical Impact: System accessWhere: From remoteSoftware: AOL Instant Messenger 5.xDescription:Ryan McGeehan has reported a vulnerability in AOL Instant Messenger (AIM), which can be exploited by malicious people to compromise a user's system.The vulnerability is caused due to a boundary error within the handling of "Away" messages and can be exploited to cause a stack-based buffer overflow by supplying an overly long "Away" message (about 1024 bytes). A malicious website can exploit this via the "aim:" URI handler by passing an overly long argument to the "goaway?message" parameter.Successful exploitation allows execution of arbitrary code on a user's system when e.g. a malicious website is visited with certain browsers.The vulnerability has been confirmed in version 5.5.3595. Other versions may also be affected.NOTE: Various other issues were also reported, where a large amount of resources can be consumed on a user's system.Read Advisory Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.