|
A remote overflow exists in AOL Instant Messenger. Instant Messenger fails to correctly limit the size of the value passed to the goaway function in the away feature resulting in a buffer overflow. A malicous user can create a specially crafted URI link that uses the 'aim:' handler and a long message value for the goaway parameter and post the link to a webpage or email. When a victim clicks on this link, or views an html document that invokes this link (such as <iframe>), the code included in the malicious URI may overwrite a Structured Exception Handler pointer which may be used to insert arbitrary code onto the stack. Once on the stack, the arbitrary code could then be executed resulting in a loss of integrity.
|