Advertisement
Promo

Security threats Toolkit

AOL: Fix for critical IM flaw due this week

Graeme Wearden ZDNet.co.uk

Published: 10 Aug 2004 15:20 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

AOL acknowledged on Tuesday that its Instant Messenger client is vulnerable to a buffer-overflow attack, and promised that a fix would be available to users within days.

"We have been working on a resolution in tandem with iDefense for more than a month," said Krista Thomas of AOL's corporate communications division.

"The issue has been fixed in our new client update beta, which will go live later this week," Thomas added.

News of the vulnerability hit the Web late on Monday after Internet Security Systems and Secunia reported that AOL IM contained a serious security hole that could allow malicious hackers to take control of a user's PC.

"The vulnerability is caused due to a boundary error within the handling of 'away' messages and can be exploited to cause a stack-based buffer overflow by supplying an overly long 'away' message (about 1,024 bytes). A malicious Web site can exploit this via the 'aim:' URI handler by passing an overly long argument to the 'goaway?message' parameter," reported Secunia. Secunia described the vulnerability as "highly critical".

Once the buffer overflow has been executed, a malicious hacker could then direct the client PC to a Web site where more code could be downloaded.

Thomas said that AOL is grateful to "Matt Murphy and iDefense for their assistance to responsibly address this issue."

The client update beta due this week will be located at AOL's Instant Messenger site. In the meantime, iDefense has provided a workaround that can be used until the new AOL IM beta version is available.

iDefense said it does not yet know of any exploits that take advantage of the vulnerability but warned that the threat should not be taken lightly.

"This is a very serious situation for AOL users at this time," said Ken Dunham, director of malicious code for iDefense. "IM is more dangerous than email. You read email throughout the day. But if your buddy sends you an instant message, you read it instantly. So, from a threat metric, it's a whole lot scarier. You can have really fast worms over IM."

CNET News.com's Dawn Kawamoto contributed to this report.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
55 out of 114 people found this useful


Full Talkback thread

1 comment

  1. my screen is all pink . How does it get to be whit... patricia picquelle

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters