Buffer Overflow in America Online Instant Messenger
A buffer overflow exists in AOL Instant Messenger (AIM) that an attacker can use to remotely execute commands on the vulnerable system.
January 8, 2002
Reported January 1, 2002, by MattConover.
VERSIONS AFFECTED
AOL Instant Messenger 4.8 (Beta) and 4.7 for Windows
DESCRIPTION
Abuffer overflow exists in AOL Instant Messenger (AIM) that an attacker can useto remotely execute commands on the vulnerable system. A buffer overruncondition in the parsing code used to parse game requests causes thisvulnerability. Users can find details about this vulnerability on thediscoverer’s Web site.
VENDOR RESPONSE
Thevendor, AOL, has patched its servers tocorrect this vulnerability. AOL's servers now have an overly long game requestparsed so that the vulnerability no longer triggers the overflow on the AIMclient.
CREDIT
Discovered by MattConover of w00w00 SecurityDevelopment.
About the Author
You May Also Like