'Critical' flaw seen in AOL Instant Messenger
Takeaway: A hacker could use the "Away" message feature to take control of a PC, according to experts.
Stay on top of the latest tech news with our free IT News Digest e-newsletter, delivered each weekday. Automatically sign up today!
By
Graeme Wearden
CNET News.com
Two security companies say that AOL's Instant Messenger application contains a serious vulnerability that could allow malicious hackers to take control of a user's PC.
According to
"The vulnerability is caused due to a boundary error within the handling of 'Away' messages and can be exploited to cause a stack-based buffer overflow by supplying an overly long 'Away' message" of about 1,024 bytes, Secunia said.
Once the buffer overflow has been executed, a malicious hacker could then direct the client PC to a Web site where more code could be downloaded.
Secunia has said that an updated version of
AOL UK was not immediately able to supply more information.
Graeme Wearden of
SponsoredWhite Papers, Webcasts, and Downloads
- Microsoft SQL Server 2005: Deployment and Tests in an iSCSI SAN Dell EqualLogic
- Enhancing Desktop and Laptop Security Performance with Disk Defragmentation Diskeeper
- Next Generation Mobility Now Sprint
- New Release - Diskeeper 2008 with InvisiTasking: It's Smart. It's Transparent. It Will Take Your PC from Zero to Sixty--Automatically! Diskeeper
- How File Fragmentation Occurs on Windows XP / Windows Server 2003 Diskeeper
Article Categories
- Security
- Security Solutions, IT Locksmith
- Networking and Communications
- E-mail Administration NetNote, Cisco Routers and Switches
- CIO and IT Management
- Project Management, CIO Issues, Strategies that Scale
- Desktops, Laptops & OS
- Windows 2000 Professional, Microsoft Word, Microsoft Excel, Microsoft Access, Windows XP,
- Data Management
- Oracle, SQL Server
- Servers
- Windows NT, Linux NetNote, Windows Server 2003
- Career Development
- Geek Trivia
- Software/Web Development
- Web Development Zone, Visual Basic, .NET
