CHAT: AOL Instant Messenger Away Message Remote Buffer Overflow

This signature detects attempts to exploit a known vulnerability in the AOL Instant Messenger. A successful attack could allow the attacker to execute arbitrary code on the targeted system. Failed exploit attempts could result in a denial of service condition.

Extended Description

AOL Instant Messenger is reported prone to a remote buffer overflow vulnerability when processing a malformed 'Away' message. This vulnerability may allow a remote attacker to execute arbitrary code on a vulnerable computer to gain unauthorized access. AOL Instant Messenger versions 5.5.3595 and 5.5 are reported vulnerable to this issue, however, other versions may be affected as well.

Affected Products

Aol instant_messenger

References

BugTraq: 10889

CVE: CVE-2004-0636

Short Name
CHAT:AIM:OVERFLOW:AIM-HTTP-AWAY
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
CHAT
Keywords
AOL Away Buffer CVE-2004-0636 Instant Message Messenger Overflow Remote bid:10889
Release Date
10/09/2006
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Aol

CVSS Score

10.0

Found a potential security threat?