AOL Instant Messenger Getfile Screenname Buffer Overrun Vulnerability
BID:8825
Info
AOL Instant Messenger Getfile Screenname Buffer Overrun Vulnerability
| Bugtraq ID: | 8825 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 15 2003 12:00AM |
| Updated: | Oct 15 2003 12:00AM |
| Credit: | Discovery of this issue is credited to AngryB <[email protected]> and KrazySnake <[email protected]>. |
| Vulnerable: |
AOL Instant Messenger 5.2.3292 |
| Not Vulnerable: |
AOL Instant Messenger 5.5.3415 Beta |
Discussion
AOL Instant Messenger Getfile Screenname Buffer Overrun Vulnerability
A remotely exploitable buffer overrun vulnerability has been reported in AOL Instant Messenger (AIM). Attackers may exploit this by enticing a user of the client to follow a maliciously constructed AIM URI (using the AIM protocol handler) that performs a "getfile" operation with an overly long value as the screenname.
A remotely exploitable buffer overrun vulnerability has been reported in AOL Instant Messenger (AIM). Attackers may exploit this by enticing a user of the client to follow a maliciously constructed AIM URI (using the AIM protocol handler) that performs a "getfile" operation with an overly long value as the screenname.
Exploit / POC
AOL Instant Messenger Getfile Screenname Buffer Overrun Vulnerability
The researchers who discovered this vulnerability have developed an exploit which is not publicly available or known to be circulating in the wild.
The researchers who discovered this vulnerability have developed an exploit which is not publicly available or known to be circulating in the wild.
Solution / Fix
AOL Instant Messenger Getfile Screenname Buffer Overrun Vulnerability
Solution:
The vendor has addressed this issue in AIM 5.5.3415 Beta.
AOL Instant Messenger 5.2.3292
Solution:
The vendor has addressed this issue in AIM 5.5.3415 Beta.
AOL Instant Messenger 5.2.3292
-
AOL AIM 5.5.3415 Beta
http://www.aim.com/get_aim/win/win_beta.adp
References
AOL Instant Messenger Getfile Screenname Buffer Overrun Vulnerability
References:
References:
- AOL Instant Messenger Home Page (AOL)
- Buffer Overflow in AOL Instant Messager's screenname parameter of getfile. (Digital Pranksters)