AOL Instant Messenger Font Denial of Service Vulnerability
BID:3756
Info
AOL Instant Messenger Font Denial of Service Vulnerability
| Bugtraq ID: | 3756 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2001-1421 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 06 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | Discovered and posted to Bugtraq by Robbie Saunders <[email protected]>. |
| Vulnerable: |
AOL Instant Messenger 4.7 AOL Instant Messenger 4.6 AOL Instant Messenger 4.5 AOL Instant Messenger 4.4 AOL Instant Messenger 4.3 AOL Instant Messenger 4.2 AOL Instant Messenger 4.1 AOL Instant Messenger 4.0 |
| Not Vulnerable: | |
Discussion
AOL Instant Messenger Font Denial of Service Vulnerability
A vulnerability exists in AOL Instant Messenger (AIM) which could cause the AIM client to stop responding.
Attacks can be launched if an instant message containing an unusual number of character fonts followed by the '<hr>' HTML comment, is sent and received by an AIM recipient. Restart of the application may be required in order to regain normal functionality.
It should be noted that HTML comments other than '<hr>' could successfully exploit this issue.
In addition, this vulnerability may also affect Netscape's AIM client.
A vulnerability exists in AOL Instant Messenger (AIM) which could cause the AIM client to stop responding.
Attacks can be launched if an instant message containing an unusual number of character fonts followed by the '<hr>' HTML comment, is sent and received by an AIM recipient. Restart of the application may be required in order to regain normal functionality.
It should be noted that HTML comments other than '<hr>' could successfully exploit this issue.
In addition, this vulnerability may also affect Netscape's AIM client.
Exploit / POC
AOL Instant Messenger Font Denial of Service Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
AOL Instant Messenger Font Denial of Service Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
AOL Instant Messenger Font Denial of Service Vulnerability
References:
References: