What is the BigBlueNetwork?

News Categories

Post a news story

Join other instant messaging fans in our live IRC chat room. Click here to launch our java chat, or visit irc.bigblueball.com #bigblueball

Latest News

News Feeds

Add to My Yahoo!
  Help
  Help

 Got instant messaging questions? Get answers in our forums. Sign up now for free!


Front Page > Site News & Announcements > Instant Messaging News > AIM News

Serious Security Hole Discovered in AIM

Posted by Jeff Jeff is offline on 09-26-2007, 06:55 PM  

Researchers at Core Security Technologies have issued an advisory disclosing a vulnerability that could severely impact millions of registered AOL Instant Messenger (AIM) users. By exploiting this vulnerability, an attacker could remotely execute code on a user's computer and exploit Internet Explorer bugs without permission or interaction from the user.

"This vulnerability poses a significant security risk to millions of AIM users." said Iván Arce, CTO at Core Security Technologies. "Core Security has alerted AOL to this threat and has provided full technical details about the vulnerability so that they can address it in their products. Since we notified AOL, this vulnerability has emerged on several public bug-tracking websites. Therefore, we believe it is necessary to bring precise details about this issue to light immediately, so that AIM users and organizations using AIM can be made aware of the threat, assess their risk, and take the appropriate measures to ensure that they are protected."

The security flaw affects AIM 6.1, AIM Lite, AIM Pro and AIM 6.2 Beta. BigBlueBall recommends that you either downgrade to an non-vulnerable version (AIM 5.9) or upgrade to the latest beta (AIM 6.5). As an alternative, you can also use the web-based AIM Express, or a third-party web client such as Meebo.
Reply With Quote

View Comments   Show Printable Version   Email this Page


 

Comments

Jeff says
09-28-2007, 12:53 AM
UPDATE

In a response e-mailed to InformationWeek, an AOL spokesman said its technicians are working on the problem.

"The safety and security of AIM users is of utmost importance to us," she wrote. "To that end, we quickly take the necessary steps to block malicious content from reaching our users. We have addressed the issues that Core Security has brought to us on the server side. We are comfortable with the server side fixes we have in place, but we are also working on a client fix."
Reply With Quote
Reply



Currently Active Users Viewing This Topic: 1 (0 members and 1 guests)
 
Topic Tools


Similar Topics
Topic Replies Last Post
AIM clients - How to put the lockdown on security! 14 08-02-2008 06:05 PM
AIM Away Message Security Hole Found 0 08-10-2004 01:00 AM
Back Doors in AIM Security Tool Irk Pros 0 01-09-2002 01:00 AM
Utah Student Defends Handling of AIM Security Flaw 0 01-03-2002 01:00 AM
AOL IM Security Hole: Sign of Things To Come? 0 10-05-2001 01:00 AM

 
All times are GMT -5. The time now is 04:13 AM.
Return to the BigBlueBall.com homepageHome | Contact Us | Privacy Statement | Advertise | Top
Powered by vBulletin® Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 RC6
Content Relevant URLs by vBSEO 3.0.0 RC6
©1999 - 2008 BigBlueBall.com All rights reserved.