AOL AIM 'sipXtapi.dll' Multiple Buffer Overflow Vulnerabilities
BID:36849
Info
AOL AIM 'sipXtapi.dll' Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 36849 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 28 2009 12:00AM |
| Updated: | Oct 28 2009 04:57PM |
| Credit: | wushi of team509 |
| Vulnerable: |
AOL Instant Messenger 6.8 |
| Not Vulnerable: |
AOL Instant Messenger 6.8.7.7 |
Discussion
AOL AIM 'sipXtapi.dll' Multiple Buffer Overflow Vulnerabilities
AOL AIM is prone to multiple buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on user-supplied data.
Successful exploits may allow attackers to execute arbitrary code with the privileges of a user running the software or cause denial-of-service conditions.
Reports indicate that versions prior to AOL AIM 6.8.7.7 are vulnerable.
AOL AIM is prone to multiple buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on user-supplied data.
Successful exploits may allow attackers to execute arbitrary code with the privileges of a user running the software or cause denial-of-service conditions.
Reports indicate that versions prior to AOL AIM 6.8.7.7 are vulnerable.
Exploit / POC
AOL AIM 'sipXtapi.dll' Multiple Buffer Overflow Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
AOL AIM 'sipXtapi.dll' Multiple Buffer Overflow Vulnerabilities
Solution:
Reportedly, the vendor has released an update, but Symantec has not confirmed this. Please see the references for more information.
Solution:
Reportedly, the vendor has released an update, but Symantec has not confirmed this. Please see the references for more information.
References
AOL AIM 'sipXtapi.dll' Multiple Buffer Overflow Vulnerabilities
References:
References:
- AOL AIM SIPFoundry sipXtapi RTCP Processing Heap Overflow Vulnerability (Zero Day Initiative)
- AOL AIM SIPFoundry sipXtapi RTP Processing Heap Overflow Vulnerability (Zero Day Initiative)
- AOL Instant Messenger Home Page (AOL)