Overview
A buffer overflow exists in the AOL Instant Messenger (AIM) client versions 3.5.x and prior when accepting the screenname from the command line, or through the aim protocol.
Description
AIM installs a protocol on the machine that enables people to post links on their websites, or send them in email messages to friends. For example: <a href="aim:goim?screenname=myname">Send me an instant message here.</a> |
Impact
A denial of service against the client can occur. |
Solution
Upgrade to a version of AIM higher than 3.5.x. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was discovered by Joe Testa.
This document was written by Jason Rafail.
Other Information
CVE IDs: | None |
Severity Metric: | 1.06 |
Date Public: | 2000-03-15 |
Date First Published: | 2002-01-16 |
Date Last Updated: | 2002-01-31 21:53 UTC |
Document Revision: | 10 |