AOL Instant Messenger Multiple DoS

medium Nessus Network Monitor Plugin ID 1252

Synopsis

The remote host is vulnerable to several denial of service attacks

Description

The remote host is running AOL Instant Messenger (AIM). Versions prior to and including 4.7 of AIM contain multiple buffer overflows that may be exploited when AIM tries to process exceptionally long comment strings in chat invite messages, long filenames (game names, buddy list names...), large amounts of font types in a message, or large Buddy Icons. Exploitation of these vulnerabilities can lock up or crash a victim's AIM client leading to a denial of service attack.

Solution

Upgrade to the latest version of AOL Instant Messenger

Plugin Details

Severity: Medium

ID: 1252

Published: 8/20/2004

Updated: 3/6/2019

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Temporal Vector: CVSS:3.0/E:H/RL:U/RC:X

Vulnerability Information

CPE: cpe:/a:aol:aim

Reference Information

CVE: CVE-2001-1417, CVE-2001-1419, CVE-2001-1420, CVE-2001-1421

BID: 3408, 3756, 3398, 3407