AOL Instant Messenger Remote Buffer Overflow
BID:3769
Info
AOL Instant Messenger Remote Buffer Overflow
| Bugtraq ID: | 3769 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 02 2002 12:00AM |
| Updated: | Jan 02 2002 12:00AM |
| Credit: | This vulnerability was discovered by Matt Conover <[email protected]>, nocarrier, napster, and w00w00 and posted to Bugtraq by Matt Conover <[email protected]>. |
| Vulnerable: |
AOL Instant Messenger 4.8.2616 AOL Instant Messenger 4.7.2480 AOL Instant Messenger 4.7 AOL Instant Messenger 4.6 AOL Instant Messenger 4.5 AOL Instant Messenger 4.4 AOL Instant Messenger 4.3.2229 AOL Instant Messenger 4.3 |
| Not Vulnerable: | |
Discussion
AOL Instant Messenger Remote Buffer Overflow
AOL Instant Messenger (AIM) is a real time messaging service.
The vulnerability exists in the way that AIM parses a game request with a TLV (type, length, value) type of 0x2711. This type of game request is prone to a buffer overflow which could allow a remote user to obtain the same privileges of the user who is currently logged on.
It is important to note that there is currently no way for an AIM user to block this type of request.
**AOL has made modifications to their AIM servers to prevent this vulnerability from being exploited through their servers. However, the underlying problem still exists in the client software which could still be exploited using something similar to a man in the middle attack or if an attacker can bypass the filters on the AIM servers.
AOL Instant Messenger (AIM) is a real time messaging service.
The vulnerability exists in the way that AIM parses a game request with a TLV (type, length, value) type of 0x2711. This type of game request is prone to a buffer overflow which could allow a remote user to obtain the same privileges of the user who is currently logged on.
It is important to note that there is currently no way for an AIM user to block this type of request.
**AOL has made modifications to their AIM servers to prevent this vulnerability from being exploited through their servers. However, the underlying problem still exists in the client software which could still be exploited using something similar to a man in the middle attack or if an attacker can bypass the filters on the AIM servers.
Exploit / POC
AOL Instant Messenger Remote Buffer Overflow
An exploit has been provided by Matt Conover ([email protected]):
An exploit has been provided by Matt Conover ([email protected]):
Solution / Fix
AOL Instant Messenger Remote Buffer Overflow
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
AOL Instant Messenger Remote Buffer Overflow
References:
References:
- AIM Filter (Wicon Software)
- AOL Instant Messenger Home Page (AOL)
- W00W00 (W00W00 Homepage)