Buffer Overflow in America Online Instant Messenger

A buffer overflow exists in AOL Instant Messenger (AIM) that an attacker can use to remotely execute commands on the vulnerable system.

Ken Pfeil

January 8, 2002

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported January 1, 2002, by MattConover.

VERSIONS AFFECTED

  • AOL Instant Messenger 4.8 (Beta) and 4.7 for Windows

 

DESCRIPTION

Abuffer overflow exists in AOL Instant Messenger (AIM) that an attacker can useto remotely execute commands on the vulnerable system. A buffer overruncondition in the parsing code used to parse game requests causes thisvulnerability. Users can find details about this vulnerability on thediscoverer’s Web site.

 


VENDOR RESPONSE

 

Thevendor, AOL, has patched its servers tocorrect this vulnerability. AOL's servers now have an overly long game requestparsed so that the vulnerability no longer triggers the overflow on the AIMclient.

 

CREDIT
Discovered by MattConover of w00w00 SecurityDevelopment.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like