Bugtraq mailing list archives

Re: AOL Instant Messenger URL Crash


From: elhoward () MARKL COM (Eric L. Howard)
Date: Wed, 21 Apr 1999 14:30:40 -0400


I haven't been able to duplicate this on any 2.0.8* builds...I've tested about
15 different people and none in the 2.0.8* builds were affected.

All others tested were in the 2.0.9* build and died immediately, some causing
the user to have to reboot, all rendering AIM completly unable to be restarted
for several minutes after the Dr. Watson cleared on NT.

        ~ELH~

At a certain time now past, Adam Brown spake thusly:
There is a bug in the newer versions of AOL's Instant Messenger that will
cause the client to crash when exploited.  All builds of version 2.0 that
I've tested seem to be vulnerable, although I have not done extensive
version testing.  AOL was notified of this about two weeks ago.  To exploit
this bug, send a hyperlink in this format: aim:addbuddy?=screenname

Have fun,

SpunOne

http://www.fazed.net

http://www.webzone.net



--
E r i c  L.  H o w a r d                     e l h o w a r d @ m a r k l . c o m
////////////////////////////////////////////////////////////////////////////////
"There is nothing in the world more dangerous than sincere ignorance and
 conscientious stupidity... You have a moral responsibility to be intelligent."
                                                - Dr. Martin Luther King Jr.



Current thread: