[10304] in bugtraq

home help back first fref pref prev next nref lref last post

Re: AOL Instant Messenger URL Crash

daemon@ATHENA.MIT.EDU (Eric L. Howard)
Wed Apr 21 20:27:25 1999

Date: 	Wed, 21 Apr 1999 14:30:40 -0400
Reply-To: "Eric L. Howard" <elhoward@MARKL.COM>
From: "Eric L. Howard" <elhoward@MARKL.COM>
To: BUGTRAQ@NETSPACE.ORG

I haven't been able to duplicate this on any 2.0.8* builds...I've tested about
15 different people and none in the 2.0.8* builds were affected.

All others tested were in the 2.0.9* build and died immediately, some causing
the user to have to reboot, all rendering AIM completly unable to be restarted
for several minutes after the Dr. Watson cleared on NT.

	~ELH~

At a certain time now past, Adam Brown spake thusly:
>There is a bug in the newer versions of AOL's Instant Messenger that will
>cause the client to crash when exploited.  All builds of version 2.0 that
>I've tested seem to be vulnerable, although I have not done extensive
>version testing.  AOL was notified of this about two weeks ago.  To exploit
>this bug, send a hyperlink in this format: aim:addbuddy?=screenname
>
>Have fun,
>
>SpunOne
>
>http://www.fazed.net
>
>http://www.webzone.net
>


--
E r i c  L.  H o w a r d	             e l h o w a r d @ m a r k l . c o m
////////////////////////////////////////////////////////////////////////////////
"There is nothing in the world more dangerous than sincere ignorance and
 conscientious stupidity... You have a moral responsibility to be intelligent."
                                                - Dr. Martin Luther King Jr.

home help back first fref pref prev next nref lref last post