AOL Instant Messenger - Highly critical vuln found . . .

For all tech/computer related or even internet related discussions not covered in other sections. Also iPad, iPhone, iPod and multimedia discussions.

Moderators: profman, Josh, Don_HH2K

AOL Instant Messenger - Highly critical vuln found . . .

Postby DJGM » Mon 09 Aug, 2004 5:55 pm

A rather serious security hole has been found in AOL Instant Messenger.

Secunia wrote:AOL Instant Messenger "Away" Message Buffer Overflow Vulnerability

Secunia Advisory: SA12198 Print Advisory
Release Date: 2004-08-09

Critical: [*][*][*][*][ ]
Highly critical
Impact: System access
Where: From remote

Software: AOL Instant Messenger 5.x

Description: Ryan McGeehan has reported a vulnerability
in AOL Instant Messenger (AIM), which potentially can be
exploited by malicious people to compromise a user's system.


Also . . .

Secunia wrote:The vulnerability has been confirmed in v5.5.3595.
Other versions may also be affected.

NOTE: Various other issues were also reported, where a large
amount of resources can be consumed on a user's system.

Solution:
The vendor was contacted but has not responded.

Use another product.



Full technical details available in the Secunia advisory . . .
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.2) Gecko/20040803
SeaMonkey = Swiss Army Knife: It's versatile, reliable, and contains useful tools.
Windows Internet Explorer = Old Swiss Cheese: Full of holes, and it stinks!
User avatar
DJGM
diamond member
diamond member
 
Posts: 4572
Joined: Wed 19 Jun, 2002 1:03 pm
Location: Manchester, England, UK

Postby Z_God » Mon 09 Aug, 2004 7:53 pm

It only seems to apply to the Windows version of the AIM.com client or does it also apply to the Netscape version of AIM, that I would expect most Sillydog visitors to use ;)
UserAgent: Mozilla/5.0 (compatible; Konqueror/3.2; Linux) (KHTML, like Gecko)
Z_God
member
member
 
Posts: 40
Joined: Tue 27 Jul, 2004 1:52 pm
Location: Netherlands (Amersfoort)

Postby Don_HH2K » Mon 09 Aug, 2004 8:08 pm

I doubt this bug is present in the Netscape version, that's integrated into Netscape. NIM is not a full port of AIM, rather just a different version (notice that AIM uses ActiveX controls while NIM uses DLL files). Because AIM uses ActiveX controls, they can use that as a backdoor as well, so that also poses a problem for MS to update (once again!!!).
Although, with the Windows GDI leak, you don't know if it's a buffer overflow or just having too many windows/tabs open.
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.4) Gecko/20030624 Netscape/7.1 (ax)
Laptop: HP Compaq nx6325 - Turion 64 X2 @ 2GHz, 2GB DDR2, 100GB HD, ATI Radeon X300, 15" LCD, Seven Pro
Handheld: Palm Treo 650 - Intel PXA270 @ 312MHz, 10MB RAM, 32MB flash, 2.7" LCD, Palm OS 5.4
User avatar
Don_HH2K
Moderator
Moderator
 
Posts: 5112
Joined: Sun 09 May, 2004 3:59 pm

Postby Antony » Mon 09 Aug, 2004 8:34 pm

AIM is the only instant messaging I use. I use Apple's iChat.

Now, is the iChat safe?
UserAgent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/125.2 (KHTML, like Gecko) Safari/125.8
User avatar
Antony
diamond member
diamond member
 
Posts: 14509
Joined: Tue 18 Jun, 2002 11:36 pm
Location: Sydney, Australia

Postby Don_HH2K » Mon 09 Aug, 2004 8:38 pm

iChat is probably safe as well, since it's more like Trillian than AIM, in the sense that it's not the same code (or is based on the same code) as AIM.

Secunia advises to use another product, so I'm guessing they are backing the fact that other programs do not have this vulnerability.
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.4) Gecko/20030624 Netscape/7.1 (ax)
Laptop: HP Compaq nx6325 - Turion 64 X2 @ 2GHz, 2GB DDR2, 100GB HD, ATI Radeon X300, 15" LCD, Seven Pro
Handheld: Palm Treo 650 - Intel PXA270 @ 312MHz, 10MB RAM, 32MB flash, 2.7" LCD, Palm OS 5.4
User avatar
Don_HH2K
Moderator
Moderator
 
Posts: 5112
Joined: Sun 09 May, 2004 3:59 pm

Postby Al » Tue 10 Aug, 2004 2:27 pm

Aol may have to stop using ActiveX. And I think iChat is probaly safe
UserAgent: Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.7) Gecko/20040803 Firefox/0.9.3
User of Firefox :ff: 3.0 on Windows XP
User avatar
Al
diamond member
diamond member
 
Posts: 1694
Joined: Fri 20 Dec, 2002 1:08 pm

Postby Andrew T. » Thu 12 Aug, 2004 3:44 pm

I also see that the vulnerability does not affect the older AOL Instant Messanger 4.x releases, that were bundled with Netscape Communicator 4.x and which I use on Windows 95. I doubt that they utilize ActiveX controls either.
UserAgent: Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.7) Gecko/20040616
User avatar
Andrew T.
diamond member
diamond member
 
Posts: 1228
Joined: Fri 14 Mar, 2003 11:37 pm
Location: Somewhere beyond the sea

Postby Don_HH2K » Thu 12 Aug, 2004 5:15 pm

It appears that those used both ActiveX (OCM) files and dynamic libraries (DLL).
I may be wrong, but would someone be able to verify this by looking at AIM's SmartUpdate JAR for Communicator 4.8?
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.4) Gecko/20030624 Netscape/7.1 (ax)
Laptop: HP Compaq nx6325 - Turion 64 X2 @ 2GHz, 2GB DDR2, 100GB HD, ATI Radeon X300, 15" LCD, Seven Pro
Handheld: Palm Treo 650 - Intel PXA270 @ 312MHz, 10MB RAM, 32MB flash, 2.7" LCD, Palm OS 5.4
User avatar
Don_HH2K
Moderator
Moderator
 
Posts: 5112
Joined: Sun 09 May, 2004 3:59 pm

Postby Wellander » Thu 12 Aug, 2004 5:24 pm

Hi,
Most programs use dll's
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.7.2) Gecko/20040803
Wellander
diamond member
diamond member
 
Posts: 2603
Joined: Mon 21 Oct, 2002 6:37 pm

Postby Don_HH2K » Thu 12 Aug, 2004 5:31 pm

Wellander wrote:Hi,
Most programs use dll's

That is true, but AIM uses a combination of DLLs and ActiveX controls.
If you have AIM installed, go to your AIM install directory, there will be multiple ActiveX controls and DLL files.
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.4) Gecko/20030624 Netscape/7.1 (ax)
Laptop: HP Compaq nx6325 - Turion 64 X2 @ 2GHz, 2GB DDR2, 100GB HD, ATI Radeon X300, 15" LCD, Seven Pro
Handheld: Palm Treo 650 - Intel PXA270 @ 312MHz, 10MB RAM, 32MB flash, 2.7" LCD, Palm OS 5.4
User avatar
Don_HH2K
Moderator
Moderator
 
Posts: 5112
Joined: Sun 09 May, 2004 3:59 pm

Postby Al » Thu 12 Aug, 2004 6:51 pm

Good girfe that I don't use AIM, does MSN Messenger use ActiveX scripts?
UserAgent: Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.7) Gecko/20040803 Firefox/0.9.3
User of Firefox :ff: 3.0 on Windows XP
User avatar
Al
diamond member
diamond member
 
Posts: 1694
Joined: Fri 20 Dec, 2002 1:08 pm

Postby Don_HH2K » Thu 12 Aug, 2004 7:11 pm

Al wrote:Good girfe that I don't use AIM, does MSN Messenger use ActiveX scripts?

Of course it does, it's Microsoft software!!
If you think about it, the small ad down at the bottom is probably being hosted by IE.
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.4) Gecko/20030624 Netscape/7.1 (ax)
Laptop: HP Compaq nx6325 - Turion 64 X2 @ 2GHz, 2GB DDR2, 100GB HD, ATI Radeon X300, 15" LCD, Seven Pro
Handheld: Palm Treo 650 - Intel PXA270 @ 312MHz, 10MB RAM, 32MB flash, 2.7" LCD, Palm OS 5.4
User avatar
Don_HH2K
Moderator
Moderator
 
Posts: 5112
Joined: Sun 09 May, 2004 3:59 pm

Postby Al » Thu 12 Aug, 2004 7:17 pm

OH brother... I hate MS software, except for NT based and VPC
UserAgent: Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.7) Gecko/20040803 Firefox/0.9.3
User of Firefox :ff: 3.0 on Windows XP
User avatar
Al
diamond member
diamond member
 
Posts: 1694
Joined: Fri 20 Dec, 2002 1:08 pm

Postby Mandrake » Thu 12 Aug, 2004 7:20 pm

Then why do you use it?
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7) Gecko/20040803 Firefox/0.9.3
Core i7 920 | ASUS P6T Deluxe v2 | 3TB+ HDD | 12GB Corsair DDR3 | Radeon 4890 Xfire | X-Fi Titanium Fatal1ty | Logitech Z-5500 Speakers | Dell 3008WFP | Seven RC1
User avatar
Mandrake
Moderator
Moderator
 
Posts: 4193
Joined: Fri 13 Sep, 2002 6:35 am

Postby Al » Thu 12 Aug, 2004 7:24 pm

Mandrake wrote:Then why do you use it?

Heck I bought it in 2000 because it was cheap and Macs are expensive and they still are, but I plan to switch to a PBookG4
UserAgent: Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.7) Gecko/20040803 Firefox/0.9.3
User of Firefox :ff: 3.0 on Windows XP
User avatar
Al
diamond member
diamond member
 
Posts: 1694
Joined: Fri 20 Dec, 2002 1:08 pm

Next

Return to General Computing and Tech

Who is online

Registered users: Google [Bot], James