vendor:
AIM
by:
SecurityFocus
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: AIM
Affected Version From: AIM versions prior to 4.3.2229
Affected Version To: AIM versions prior to 4.3.2229
Patch Exists: YES
Related CWE: CVE-2002-0674
CPE: a:aol:aim
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2002
Buffer Overflow in AOL Instant Messenger
A buffer overflow vulnerability exists in versions of AOL Instant Messenger (AIM) previous to 4.3.2229. By sending a specially crafted URL, using the 'aim:' protocol, comprised of 'goim' and 'screenname' parameters, it is possible for a remote user to overflow the buffer during a memory copy operation and execute arbitrary code. Even if AIM is not running, if a user clicks or otherwise activates a malicious aim:// url, the overflow will occur.
Mitigation:
Upgrade to the latest version of AIM