News AOL Messenger has highly critical hole

Discussion in 'Article Discussion' started by GreatOldOne, 9 Aug 2004.

  1. GreatOldOne

    GreatOldOne Wannabe Martian

    Joined:
    29 Jan 2002
    Posts:
    12,092
    Likes Received:
    112
    Now I'm sure none of you would be caught dead using AOHELL, but its news all the same. ;)

    This from the Inq:

    A CRITICAL ERROR IN AOL Instant Messenger, or AIM, has been reported at security website secunia.com. The vulnerability in the highly popular chat program was spotted by a fella' called Ryan McGeehan (no relation), which can be exploited to compromise a user's system.

    It turns out that if a user sets his or her status to "away" – a user on "away" will automatically send back an "away message" to anyone who tries to contact them – there's a problem present. A boundary error with the handling of away messages can be used to create a stack-based buffer overflow by supplying an overly long away message, said Secunia.

    If someone performs the exploit correctly, it can potentially allow for the execution of code on the system, which could, for example, open up malicious websites in certain browsers. The problem has been reported and confirmed in version 5.5.3595, although other versions could very well be affected.

    Secunia is giving this vulnerability a "highly critical" rating, and says the only way to get around it at the moment is to use another product.


    That's all folks, but you can read it again in a slightly different font here
     
  2. r3Q

    r3Q Minimodder

    Joined:
    31 Jul 2002
    Posts:
    579
    Likes Received:
    0
    i cant wait to see all the little kiddies laptops explode :rock:

    freaking idoits.

    "WHY ARE THESE PORNO THINGS COMMING UP?!!"

    HAHAHHA :clap:
     
  3. acrimonious

    acrimonious Custom User Title:

    Joined:
    8 Nov 2002
    Posts:
    4,060
    Likes Received:
    3
    There was an error between the keyboard and the chair to start with.
     
  4. Sparrowhawk

    Sparrowhawk Wetsander

    Joined:
    14 Feb 2004
    Posts:
    584
    Likes Received:
    1
    Is this referring to the user, or the AOL programmer? (Or both...? :wallbash: )
     
  5. Dinh

    Dinh What's a Dremel?

    Joined:
    27 Jun 2004
    Posts:
    810
    Likes Received:
    0
    Well.. I know SEVERAL Exploits on aim.. Programmers dont bother to fix them.
     
  6. r3Q

    r3Q Minimodder

    Joined:
    31 Jul 2002
    Posts:
    579
    Likes Received:
    0
    rofl. i really havnt kept up with the news on it. i leave that wrechid program alone :hehe:

    damn 8 year olds and their preschool friends playing on it. :grr: they deserve to be hacked.
     
  7. DeathAwaitsU

    DeathAwaitsU I'm Back :D

    Joined:
    27 Feb 2004
    Posts:
    2,104
    Likes Received:
    19
    Can tell you beleive in children learning how to use computers at an early age :hehe:

    Death
     
  8. KryoNexus

    KryoNexus What's a Dremel?

    Joined:
    21 Jan 2004
    Posts:
    122
    Likes Received:
    0
    it could come in handy though as a defense for all the spim recieved on aim.
     
Tags: Add Tags

Share This Page