AOL Instant Messenger Escaped Character Entities DoS Vulnerability
BID:1810
Info
AOL Instant Messenger Escaped Character Entities DoS Vulnerability
| Bugtraq ID: | 1810 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Mar 02 2000 12:00AM |
| Updated: | Mar 02 2000 12:00AM |
| Credit: | Posted to Bugtraq on March 2, 2000 by cruz <[email protected]>. |
| Vulnerable: |
AOL Instant Messenger 3.5 .1808 AOL Instant Messenger 3.5 .1670 AOL Instant Messenger 3.5 .1635 AOL Instant Messenger 3.0 N AOL Instant Messenger 3.0 .1470 AOL Instant Messenger 2.5 .1598 AOL Instant Messenger 2.5 .1366 AOL Instant Messenger 2.0 N |
| Not Vulnerable: | |
Discussion
AOL Instant Messenger Escaped Character Entities DoS Vulnerability
Escaped character entities ranging from ̂ - ̋ sent to an AOL Instant Messenger client have varying effects ranging from closing of message windows to shutdown of the application. Attacks can be launched if URL references contain these particular entities. Restart of the application is required in order to regain normal functionality.
Escaped character entities ranging from ̂ - ̋ sent to an AOL Instant Messenger client have varying effects ranging from closing of message windows to shutdown of the application. Attacks can be launched if URL references contain these particular entities. Restart of the application is required in order to regain normal functionality.
Exploit / POC
AOL Instant Messenger Escaped Character Entities DoS Vulnerability
See discussion.
See discussion.
Solution / Fix
AOL Instant Messenger Escaped Character Entities DoS Vulnerability
Solution:
AOL Instant Messenger 3.5.1856 and later versions are not susceptible to this vulnerability. The latest version can be downloaded at the following location:
http://www.aol.com/aim/home.html
Solution:
AOL Instant Messenger 3.5.1856 and later versions are not susceptible to this vulnerability. The latest version can be downloaded at the following location:
http://www.aol.com/aim/home.html
References
AOL Instant Messenger Escaped Character Entities DoS Vulnerability
References:
References: