AOL Instant Messenger Away Message Remote Buffer Overflow Vulnerability
BID:10889
Info
AOL Instant Messenger Away Message Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 10889 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0636 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 09 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | Discovery is credited to Ryan McGeehan and Kevin Benes. Matt Murphy is credited with discovery as well. |
| Vulnerable: |
AOL Instant Messenger 5.5.3595 AOL Instant Messenger 5.5.3415 Beta AOL Instant Messenger 5.5 |
| Not Vulnerable: | |
Discussion
AOL Instant Messenger Away Message Remote Buffer Overflow Vulnerability
AOL Instant Messenger is reported prone to a remote buffer overflow vulnerability when processing a malformed 'Away' message. This vulnerability may allow a remote attacker to execute arbitrary code on a vulnerable computer to gain unauthorized access.
AOL Instant Messenger versions 5.5.3595 and 5.5 are reported vulnerable to this issue, however, other versions may be affected as well.
AOL Instant Messenger is reported prone to a remote buffer overflow vulnerability when processing a malformed 'Away' message. This vulnerability may allow a remote attacker to execute arbitrary code on a vulnerable computer to gain unauthorized access.
AOL Instant Messenger versions 5.5.3595 and 5.5 are reported vulnerable to this issue, however, other versions may be affected as well.
Exploit / POC
AOL Instant Messenger Away Message Remote Buffer Overflow Vulnerability
Proof of concept code has been published. John Bissell A.K.A. HighT1mes has also released an exploit designed to leverage this issue.
An exploit has been released as part of the MetaSploit Framework 2.3.
Proof of concept code has been published. John Bissell A.K.A. HighT1mes has also released an exploit designed to leverage this issue.
An exploit has been released as part of the MetaSploit Framework 2.3.
Solution / Fix
AOL Instant Messenger Away Message Remote Buffer Overflow Vulnerability
Solution:
AOL has released a new version of Instant Messenger to address this issue. Instant Messenger versions released on and subsequent to August 9, 2004 are not vulnerable.
Solution:
AOL has released a new version of Instant Messenger to address this issue. Instant Messenger versions released on and subsequent to August 9, 2004 are not vulnerable.
References
AOL Instant Messenger Away Message Remote Buffer Overflow Vulnerability
References:
References: