AOL Instant Messenger HTML Comments DoS Vulnerability
BID:3398
Info
AOL Instant Messenger HTML Comments DoS Vulnerability
| Bugtraq ID: | 3398 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2001-1419 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 29 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | Posted to the Vuln-Dev mailing list by leon <[email protected]>. |
| Vulnerable: |
AOL Instant Messenger 4.7.2480 AOL Instant Messenger 4.7 AOL Instant Messenger 4.6 AOL Instant Messenger 4.5 AOL Instant Messenger 4.4 AOL Instant Messenger 4.3.2229 AOL Instant Messenger 4.3 AOL Instant Messenger 4.2 AOL Instant Messenger 4.1 AOL Instant Messenger 4.0 |
| Not Vulnerable: | |
Discussion
AOL Instant Messenger HTML Comments DoS Vulnerability
A vulnerability exists in AOL Instant Messenger (AIM) which could cause the AIM client to stop responding.
Attacks can be launched if an instant message containing an unusual number of HTML comments, is sent and received by an AIM recipient. Restart of the application may be required in order to regain normal functionality. This has also been known to work when using the chat invite message function.
It has been reported that the majority of AOL's versions of AIM is subject to this vulnerability. This reportedly, includes Netscape's AIM client.
A vulnerability exists in AOL Instant Messenger (AIM) which could cause the AIM client to stop responding.
Attacks can be launched if an instant message containing an unusual number of HTML comments, is sent and received by an AIM recipient. Restart of the application may be required in order to regain normal functionality. This has also been known to work when using the chat invite message function.
It has been reported that the majority of AOL's versions of AIM is subject to this vulnerability. This reportedly, includes Netscape's AIM client.
Exploit / POC
AOL Instant Messenger HTML Comments DoS Vulnerability
Ceromus, First Last <[email protected]> and Robbie Saunders has developed the AIMFilter.zip exploit:
http://www.ssnbc.com/wiz/AIM%20Filter.zip
Ceromus, First Last <[email protected]> and Robbie Saunders has developed the AIMFilter.zip exploit:
http://www.ssnbc.com/wiz/AIM%20Filter.zip
Solution / Fix
AOL Instant Messenger HTML Comments DoS Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
AOL Instant Messenger HTML Comments DoS Vulnerability
References:
References:
- [ADVISORY] AOL Instant Messenger DoS (Matthew Sachs
) - AOL Instant Messenger Home Page (AOL)
- new 0day AIM DoS released (AngryPacket)