On TechRepublic: 10 lame phrases to cut from your resume
BNET Business Network:
BNET
TechRepublic
ZDNet

By Dawn Kawamoto
Posted on ZDNet News: Aug 10, 2004 3:19:00 PM

America Online acknowledged Tuesday that its AOL Instant Messenger client is vulnerable to a buffer-overflow attack and promised that a fix would be available within days.

The problem resides in the chat software's "away" function, which allows people to show their friends that they're not at the computer.

"We have been working on a resolution in tandem with iDefense for more than a month," said Krista Thomas, a spokeswoman for AOL.

The vulnerability has been fixed in the company's new client update beta, which is expected to go live later this week, Thomas added.

News of the vulnerability hit the Web late Monday after security companies Internet Security Systems and Secunia reported that AOL's IM software contained a serious security hole that could allow malicious hackers to take control of a person's PC.

Secunia described the vulnerability as "highly critical." AOL IM has 36 million active users.

"The vulnerability is caused due to a boundary error within the handling of 'Away' messages and can be exploited to cause a stack-based buffer overflow by supplying an overly long 'Away' message" of about 1,024 bytes," Secunia said.

Once the buffer overflow has been executed, a malicious hacker could then direct the client PC to a Web site where more code could be downloaded.

The vulnerability is triggered when an AOL IM user clicks on a malicious hyperlink included in an instant message or embedded in a Web page, according to AOL.

Version 5.5 and earlier versions of AOL IM are vulnerable to attack. The flaw affects all Windows versions of the application, even the instant-messaging software compiled with Microsoft Visual Studio .Net 2003 and stack protection.

AOL and iDefense have been working on the problem since July 12. The online giant and iDefense did not initially disclose the problem in order to allow time to develop a patch before the vulnerability became widely known.

The client update beta due this week will located on AOL's Instant Messenger site. In the meantime, iDefense has provided a workaround that can be used until the new AOL IM beta version is available.

iDefense said it does not yet know of any exploits that take advantage of the vulnerability but warned that the threat should not be taken lightly.

"This is a very serious situation for AOL users at this time," said Ken Dunham, director of malicious code for iDefense. "IM is more dangerous than e-mail. You read e-mail throughout the day. But if your buddy sends you an instant message, you read it instantly. So from a threat metric, it's a whole lot scarier. You can have really fast worms over IM."

Graeme Wearden of ZDNet UK reported from London. CNET News.com's Dawn Kawamoto reported from San Francisco.

America Online acknowledged Tuesday that its AOL Instant Messenger client is vulnerable to a buffer-overflow attack and promised that a fix would be available within days.

The problem resides in the chat software's "away" function, which allows people to show their friends that they're not at the computer.

"We have been working on a resolution in tandem with iDefense for more than a month," said Krista Thomas, a spokeswoman for AOL.

The vulnerability has been fixed in the company's new client update beta, which is expected to go live later this week, Thomas added.

News of the vulnerability hit the Web late Monday after security companies Internet Security Systems and Secunia reported that AOL's IM software contained a serious security hole that could allow malicious hackers to take control of a person's PC.

Secunia described the vulnerability as "highly critical." AOL IM has 36 million active users.

"The vulnerability is caused due to a boundary error within the handling of 'Away' messages and can be exploited to cause a stack-based buffer overflow by supplying an overly long 'Away' message" of about 1,024 bytes," Secunia said.

Once the buffer overflow has been executed, a malicious hacker could then direct the client PC to a Web site where more code could be downloaded.

The vulnerability is triggered when an AOL IM user clicks on a malicious hyperlink included in an instant message or embedded in a Web page, according to AOL.

Version 5.5 and earlier versions of AOL IM are vulnerable to attack. The flaw affects all Windows versions of the application, even the instant-messaging software compiled with Microsoft Visual Studio .Net 2003 and stack protection.

AOL and iDefense have been working on the problem since July 12. The online giant and iDefense did not initially disclose the problem in order to allow time to develop a patch before the vulnerability became widely known.

The client update beta due this week will located on AOL's Instant Messenger site. In the meantime, iDefense has provided a workaround that can be used until the new AOL IM beta version is available.

iDefense said it does not yet know of any exploits that take advantage of the vulnerability but warned that the threat should not be taken lightly.

"This is a very serious situation for AOL users at this time," said Ken Dunham, director of malicious code for iDefense. "IM is more dangerous than e-mail. You read e-mail throughout the day. But if your buddy sends you an instant message, you read it instantly. So from a threat metric, it's a whole lot scarier. You can have really fast worms over IM."

Graeme Wearden of ZDNet UK reported from London. CNET News.com's Dawn Kawamoto reported from San Francisco.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 14 Talkback(s)
Windows + Flaw = Redundant
Hey, for years I've listened to the anti-Mac Winblows zombies
whine like little girls that the Mac is a toy (as they went on to
complain that it didn't run enough games).

Now we have a ... (Read the rest)
Posted by: DrDude_z Posted on: 08/13/04 You are currently: a Guest | | Terms of Use
LOL.. it's actually a Windows flaw!  Xunil_Sierutuf | 08/10/04
Whoops.. I retract that..  Xunil_Sierutuf | 08/10/04
Re: Whoope.. I retract that..  PottHead | 08/10/04
Actually it could be  Spoon Jabber | 08/10/04
LOL  Qbt | 08/10/04
at one time no one felt this way  V Sanders | 08/10/04
Suck my Mac!  DrDude_z | 08/13/04
Just hearing that its AOL, the flaw is AOL  FilledOut | 08/10/04
Use a different client, then  Yagotta B. Kidding | 08/10/04
Kopete  Linux User 147560 | 08/10/04
We are all happy to hear that  EnterPrise_Analyst | 08/10/04
`Kopete  EnterPrise_Analyst | 08/10/04
Aol flaw not windows  EnterPrise_Analyst | 08/10/04
Windows + Flaw = Redundant  DrDude_z | 08/13/04

What do you think?

advertisement
Click Here
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here