Feeds

AOL AIMs to fix security flaw

Buffer the IM Slayer

  • alert
  • submit to reddit

Intelligent flash storage arrays

AOL has acknowledged a potentially serious security vulnerability affecting users of its popular AOL Instant Messenger (AIM) software. It has promised a fix within days. In the meantime, the media giant is advising concerned punters to try a beta version of its forthcoming update.

The vulnerability in current version of the IM client stems from a bug in the 'Away' function of AIM which opens the door to stack-based buffer overflow attacks. The 'Away' functions is used to let a users let people know when they are away from their desk. A bug is AIM's URL handler means that the function misbehaves when it receives very long messages. Computer crackers might exploit this behaviour to inject malicious code into vulnerable system, security firm iDefense warns.

The vulnerability has been confirmed in version 5.5.3595. Other versions may also be affected.

Exploit of the vulnerability requires that an AIM user click on a malicious URL supplied in an instant message or embedded in a Web page. The spread of mass mailing worm tells us it not hard to coax people into such risky behaviour, so a software update can't come too soon.

For now there are two options: update to AOL's beta software or block exploitation by removing the following key from the registry: 'HKEY_CLASSES_ROOT\aim'. Avoid the latter option unless you're comfortable with using Window's Registry Editor software, the misuse of which can render a system inoperable. ®

Related stories

The Great Enterprise IM love-in
AOL unveils IM for business
UK firms must monitor staff IMs
Yahoo! IM! in! flaw! flap!

Top 5 reasons to deploy VMware with Tegile

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.