AOL Instant Messenger (AIM)缓冲区溢出漏洞

AOL Instant Messenger (AIM)缓冲区溢出漏洞

漏洞ID 1106135 漏洞类型 缓冲区溢出
发布时间 2000-12-12 更新时间 2005-10-12
图片[1]-AOL Instant Messenger (AIM)缓冲区溢出漏洞-安全小百科CVE编号 CVE-2000-1094
图片[2]-AOL Instant Messenger (AIM)缓冲区溢出漏洞-安全小百科CNNVD-ID CNNVD-200101-081
漏洞平台 Windows CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/20511
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200101-081
|漏洞详情
AOLInstantMessenger(AIM)4.3.2229之前的版本存在缓冲区溢出漏洞。远程攻击者借助带有超长”src”参数的”buddyicon”命令执行任意命令。
|漏洞EXP
source: http://www.securityfocus.com/bid/2122/info

AOL Instant Messenger (AIM) is a real time messaging service for users that are on line. When AOL Instant Messenger is installed, by default it configures the system so that the aim: URL protocol connects aim:// urls to the AIM client. There exists a buffer overflow in parsing aim:// URL parameters.

The buffer overflow has to do with the parsing of parameters associated with the "buddyicon" option. The stack overflow will occur If the "Source" parameter, which arguments the buddyicon option, is more than 3000 characters in length. It may be possible to execute arbitrary code. Since this vulnerability manifests itself in an URL, a user needs only to click on the URL (which can be embedded in email, webpages, chatrooms, etc) for the flaw to be exploited.

It should be noted that the victim need only have AIM installed on their machine to be vulnerable. Even if AIM is not running, if a user clicks or otherwise activates a malicious aim:// url, the overflow will occur. Additionally it should be noted that AIM is often included/bundled with Netscape Communicator and possibly other popular software programs.

Successful exploitation of this vulnerability will lead to complete comprimise of the target host. 

aim:buddyicon?screenname=abob&groupname=asdf&Src=http://localhost/AAA...
|参考资料

来源:ATSTAKE
名称:A121200-1
链接:http://www.atstake.com/research/advisories/2000/a121200-1.txt
来源:OSVDB
名称:1692
链接:http://www.osvdb.org/1692
来源:BUGTRAQ
名称:20001214Re:AIM&@stake’sadvisory
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=97683774417132&w;=2
来源:BUGTRAQ
名称:20001213Administrivia&AOLIMAdvisory;
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=97668265628917&w;=2

相关推荐: ngIRCd 0.8.1 – Remote Denial of Service (2)

ngIRCd 0.8.1 – Remote Denial of Service (2) 漏洞ID 1054883 漏洞类型 发布时间 2005-02-05 更新时间 2005-02-05 CVE编号 N/A CNNVD-ID N/A 漏洞平台 Linux CV…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享