CVE Vulnerabilities

CVE-2002-1953

Published: Dec 31, 2002 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

Heap-based buffer overflow in the goim handler of AOL Instant Messenger (AIM) 4.4 through 4.8.2616 allows remote attackers to cause a denial of service (crash) via escaping of the screen name parameter, which triggers the overflow when the user selects Get Info on the buddy.

Affected Software

Name Vendor Start Version End Version
Instant_messenger Aol 4.4 (including) 4.4 (including)
Instant_messenger Aol 4.5 (including) 4.5 (including)
Instant_messenger Aol 4.6 (including) 4.6 (including)
Instant_messenger Aol 4.7 (including) 4.7 (including)
Instant_messenger Aol 4.7.2480 (including) 4.7.2480 (including)
Instant_messenger Aol 4.8.2616 (including) 4.8.2616 (including)
Instant_messenger Aol 4.8.2646 (including) 4.8.2646 (including)

References