AOL Instant Messenger Link Special Character Remote Heap Overflow Vulnerability
BID:5492
Info
AOL Instant Messenger Link Special Character Remote Heap Overflow Vulnerability
| Bugtraq ID: | 5492 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 18 2002 12:00AM |
| Updated: | Aug 18 2002 12:00AM |
| Credit: | Vulnerability discovery credited to a b <[email protected]> |
| Vulnerable: |
AOL Instant Messenger 4.8.2616 AOL Instant Messenger 4.8 .2646 AOL Instant Messenger 4.7.2480 AOL Instant Messenger 4.7 AOL Instant Messenger 4.6 AOL Instant Messenger 4.5 AOL Instant Messenger 4.4 |
| Not Vulnerable: | |
Discussion
AOL Instant Messenger Link Special Character Remote Heap Overflow Vulnerability
AIM is the AOL Instant Messenger. It is available for various platforms, including Linux and Microsoft Windows. This vulnerability affects the Windows client.
A problem has been reported in the handling of special characters. When an URL is sent to a user containing special characters that must be converted to addressable format, an overflow may occur. This has reportedly been reproduced to create a denial of service.
AIM is the AOL Instant Messenger. It is available for various platforms, including Linux and Microsoft Windows. This vulnerability affects the Windows client.
A problem has been reported in the handling of special characters. When an URL is sent to a user containing special characters that must be converted to addressable format, an overflow may occur. This has reportedly been reproduced to create a denial of service.
Exploit / POC
AOL Instant Messenger Link Special Character Remote Heap Overflow Vulnerability
The following procedure has been reported by a b <[email protected]> as producing a denial of service:
Craft the URL to be sent to the victim. Lets use spaces since they get
converted to %20 by AIM :). We could use other extended ASCII, etc.
Fill the whole URL up to the end (the "protected" buffer dist), which is 172
chars. (172 * 2 = 344).
The following procedure has been reported by a b <[email protected]> as producing a denial of service:
Craft the URL to be sent to the victim. Lets use spaces since they get
converted to %20 by AIM :). We could use other extended ASCII, etc.
Fill the whole URL up to the end (the "protected" buffer dist), which is 172
chars. (172 * 2 = 344).
Solution / Fix
AOL Instant Messenger Link Special Character Remote Heap Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
AOL Instant Messenger Link Special Character Remote Heap Overflow Vulnerability
References:
References: