|
|
|
![]() |
Vulnerability Note VU#990451AOL Instant Messenger vulnerable to DoS via crafted WAV fileOverviewAOL Instant Messenger (AIM) is an application that allows one peer to communicate with another. A vulnerability exists that can crash the client of a victim.I. DescriptionAIM allows users to send audio files to one another. By sending a corrupt WAV formatted file, an attacker can cause the victims client to crash.II. ImpactBy repeatedly sending this message with the file attached, a continued denial of service can be caused.III. SolutionUpgrade your client. This has been fixed in version 4.8.2540 beta.AIM permits the user to only accept messages from known/trusted peers. Enable this feature.
References
This vulnerability was discovered by Robbie Saunders. This document was written by Jason Rafail.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||