AOL Instant Messenger Buddy Icon Remote Denial of Service Vulnerability
BID:13880
Info
AOL Instant Messenger Buddy Icon Remote Denial of Service Vulnerability
| Bugtraq ID: | 13880 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-1891 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 07 2005 12:00AM |
| Updated: | Jul 12 2009 02:56PM |
| Credit: | Discovery is credited to Tom Ferris <[email protected]>. |
| Vulnerable: |
AOL Instant Messenger 5.9.3797 AOL Instant Messenger 5.5.3595 AOL Instant Messenger 5.5.3415 Beta AOL Instant Messenger 5.5 AOL Instant Messenger 5.2.3292 AOL Instant Messenger 5.1.3036 AOL Instant Messenger 5.0.2938 |
| Not Vulnerable: | |
Discussion
AOL Instant Messenger Buddy Icon Remote Denial of Service Vulnerability
AOL Instant Messenger is affected by a remote denial of service vulnerability.
An attacker can exploit this issue by crafting a malformed GIF file and use it as a Buddy Icon followed by sending an instant message to a remote user. A malicious GIF image can trigger an integer overflow, which can cause a crash in the client.
AOL Instant Messenger 5.9.3797 and prior versions are reportedly vulnerable.
AOL Instant Messenger is affected by a remote denial of service vulnerability.
An attacker can exploit this issue by crafting a malformed GIF file and use it as a Buddy Icon followed by sending an instant message to a remote user. A malicious GIF image can trigger an integer overflow, which can cause a crash in the client.
AOL Instant Messenger 5.9.3797 and prior versions are reportedly vulnerable.
Exploit / POC
AOL Instant Messenger Buddy Icon Remote Denial of Service Vulnerability
A proof of concept is available at the following locations:
http://security-protocols.com/poc/aim-DoS-.gif
http://fux0r.phathookups.com/aim-DoS.gif
It should be noted that the above proof of concept has not been verified by Symantec.
A proof of concept is available at the following locations:
http://security-protocols.com/poc/aim-DoS-.gif
http://fux0r.phathookups.com/aim-DoS.gif
It should be noted that the above proof of concept has not been verified by Symantec.
Solution / Fix
AOL Instant Messenger Buddy Icon Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
AOL Instant Messenger Buddy Icon Remote Denial of Service Vulnerability
References:
References: