Overview
AOL Instant Messenger (AIM) is an application that allows one peer to communicate with another. A buffer overflow vulnerability exists that can manipulate the configuration of the victim's client.
Description
AIM installs a URI handler that permits the use of the "aim:" protocol on the machine that enables people to post links on their websites, or send them in email messages to friends. For example: <a href="aim:goim?screenname=myname">Send me an instant message here.</a> |
Impact
An attacker can add arbitrary users to the victim's "buddy" list, or crash their client. |
Solution
Upgrade to a version of AIM higher than 3.5.x. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Our thanks to @stake
This document was written by Jason Rafail.
Other Information
CVE IDs: | CVE-2000-1094 |
Severity Metric: | 4.50 |
Date Public: | 2000-12-12 |
Date First Published: | 2002-04-05 |
Date Last Updated: | 2002-04-05 21:28 UTC |
Document Revision: | 13 |