Vulnerabilities > CVE-2005-1891 - Integer Underflow (Wrap or Wraparound) vulnerability in AOL AIM
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
The GIF parser in ateimg32.dll in AOL Instant Messenger (AIM) 5.9.3797 and earlier allows remote attackers to cause a denial of service (crash) via a malformed buddy icon that causes an integer underflow in a loop counter variable.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 20 | |
OS | 1 |
Common Weakness Enumeration (CWE)
Nessus
NASL family | Windows |
NASL id | AIM_BUDDY_ICON_OVERFLOW.NASL |
description | According to the Windows registry, the version of AOL Instant Messenger install on the remote host has an integer overflow in its GIF parser, |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 18432 |
published | 2005-06-08 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/18432 |
title | AIM Buddy Icon Overflow Vulnerability |
code |
|
References
- http://marc.info/?l=bugtraq&m=111816939928640&w=2
- http://marc.info/?l=bugtraq&m=111816939928640&w=2
- http://marc.info/?l=bugtraq&m=111817881214343&w=2
- http://marc.info/?l=bugtraq&m=111817881214343&w=2
- http://securitytracker.com/id?1014145
- http://securitytracker.com/id?1014145
- http://www.securityfocus.com/bid/13880
- http://www.securityfocus.com/bid/13880