CVE-2002-1953

Heap-based buffer overflow in the goim handler of AOL Instant Messenger (AIM) 4.4 through 4.8.2616 allows remote attackers to cause a denial of service (crash) via escaping of the screen name parameter, which triggers the overflow when the user selects "Get Info" on the buddy.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:aol:instant_messenger:4.4:*:*:*:*:*:*:*
cpe:2.3:a:aol:instant_messenger:4.5:*:*:*:*:*:*:*
cpe:2.3:a:aol:instant_messenger:4.6:*:*:*:*:*:*:*
cpe:2.3:a:aol:instant_messenger:4.7:*:*:*:*:*:*:*
cpe:2.3:a:aol:instant_messenger:4.7.2480:*:*:*:*:*:*:*
cpe:2.3:a:aol:instant_messenger:4.8.2616:*:*:*:*:*:*:*
cpe:2.3:a:aol:instant_messenger:4.8.2646:*:*:*:*:*:*:*

History

20 Nov 2024, 23:42

Type Values Removed Values Added
References () http://online.securityfocus.com/archive/1/288980 - () http://online.securityfocus.com/archive/1/288980 -
References () http://www.iss.net/security_center/static/9950.php - () http://www.iss.net/security_center/static/9950.php -
References () http://www.securityfocus.com/bid/5492 - Exploit () http://www.securityfocus.com/bid/5492 - Exploit

Information

Published : 2002-12-31 05:00

Updated : 2024-11-20 23:42


NVD link : CVE-2002-1953

Mitre link : CVE-2002-1953

CVE.ORG link : CVE-2002-1953


JSON object : View

Products Affected

aol

  • instant_messenger