AOL Instant Messenger BuddyIcon Buffer Overflow Vulnerability
BID:2122
Info
AOL Instant Messenger BuddyIcon Buffer Overflow Vulnerability
| Bugtraq ID: | 2122 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Unknown |
| Local: | Unknown |
| Published: | Dec 12 2000 12:00AM |
| Updated: | Dec 12 2000 12:00AM |
| Credit: | Discovered and posted in a security advisory by @stake Inc <www.atstake.com> on Dec 12, 2000. |
| Vulnerable: |
AOL Instant Messenger 4.2.1193 AOL Instant Messenger 4.1.2010 AOL Instant Messenger 4.0 |
| Not Vulnerable: |
AOL Instant Messenger 4.3.2229 |
Exploit / POC
AOL Instant Messenger BuddyIcon Buffer Overflow Vulnerability
The following exploit is provided by @stake <www.atstake.com>:
aim:buddyicon?screenname=abob&groupname=asdf&Src=http://localhost/AAA...
The following exploit is provided by @stake <www.atstake.com>:
aim:buddyicon?screenname=abob&groupname=asdf&Src=http://localhost/AAA...
Solution / Fix
AOL Instant Messenger BuddyIcon Buffer Overflow Vulnerability
Solution:
This vulnerability has been addressed in AOL Instant Messenger 4.3.2229: Users are advised to upgrade to the newest version.
http://www.aol.com/aim/download.html
Solution:
This vulnerability has been addressed in AOL Instant Messenger 4.3.2229: Users are advised to upgrade to the newest version.
http://www.aol.com/aim/download.html
References
AOL Instant Messenger BuddyIcon Buffer Overflow Vulnerability
References:
References: