AOL Instant Messenger Large BuddyIcon Denial of Service Vulnerability
BID:3408
Info
AOL Instant Messenger Large BuddyIcon Denial of Service Vulnerability
| Bugtraq ID: | 3408 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2001-1417 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 06 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | Posted to Bugtraq by Robbie Saunders <[email protected]> on Oct 6, 2001. |
| Vulnerable: |
AOL Instant Messenger 4.7 |
| Not Vulnerable: | |
Discussion
AOL Instant Messenger Large BuddyIcon Denial of Service Vulnerability
A vulnerability exists in AOL Instant Messenger (AIM) which could cause the AIM client to stop responding.
AIM does not properly check the size of a user's BuddyIcon when sending instant messages. Therefore, a user with an unusually large BuddyIcon image display dimensions sending instant messages, could cause target clients to stop responding.
A vulnerability exists in AOL Instant Messenger (AIM) which could cause the AIM client to stop responding.
AIM does not properly check the size of a user's BuddyIcon when sending instant messages. Therefore, a user with an unusually large BuddyIcon image display dimensions sending instant messages, could cause target clients to stop responding.
Exploit / POC
AOL Instant Messenger Large BuddyIcon Denial of Service Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
AOL Instant Messenger Large BuddyIcon Denial of Service Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
AOL Instant Messenger Large BuddyIcon Denial of Service Vulnerability
References:
References: