- Recommend:
- 0 Comments
AOL Confirms Security Hole in AIM
Flaw could leave PCs vulnerable to malicious code.
America Online admits there is a security hole in the latest versions of its AOL Instant Messenger (AIM) chat program, which corroborates findings an independent security group released Wednesday. AOL says it will fix the problem by the end of the week.
AOL has "identified the issue and developed a resolution that should be deployed in the next day or two," says Andrew Weinstein, spokesperson. The fix to the hole will take place on AOL's servers and will not require users to download patches, he says. AOL is unaware of the security problem actually impacting any users, he adds.
Buddy List Flaw
The hole, discovered by the security group W00w00, takes advantage of a flaw in the shared game features of AIM, Weinstein says. The vulnerable feature lets users invite members of their buddy list to participate in online games, but could let an attacker send malicious code to the victim's machine, w00w00 says in its advisory.
The security group also speculates that virus writers could use the bug to create a worm similar to the Code Red and Nimda worms that hit Microsoft's IIS (Internet Information Services) Web servers in July and October, respectively. In this scenario, the worm would attack vulnerable systems and spread via the buddy list on the infected PC, W00w00 says.
Helping Hand?
In a move that could potentially bring such a scenario into reality, W00w00 also posted code on its Web site that would let people use the hole for attacks. Posting full attack code follows full disclosure policy, which has been at the heart of a number of debates in the security community in recent months.
The vulnerability affects users of AIM versions 4.7 and 4.8, Weinstein says. W00w00 initially said the same thing, but later amended its findings in a post to the Bugtraq e-mail list saying that the problem impacts AIM versions as far back as 4.3.
However, AOL's Weinstein says that the only versions of the software that support the shared game feature where the vulnerability resides are versions 4.7 and 4.8.
Although Weinstein did not have exact numbers on hand, he says that AIM has more than 100 million registered users. No numbers were available as to how many users have the vulnerable versions of the software.
Would you recommend this story? YES NO
- Recommend:
- 0 Comments
-
Speed Up Everything!
PCWorld shows you the secrets to improve performance on all your hardware.
-
Become an Android authority
Play music or games, run productivity apps and essential utilities.
-
ThinkPad Edge E420 Lenovo Style in an Affordable Package
Buy now direct from Lenovo -
ThinkPad X220 Fast and light, with great input ergonomics and battery life, this powerhouse ultraportable is best-of-breed.
Buy now direct from Lenovo -
ThinkPad X120e One of the best netbooks ever, X120e has the best netbook keyboard ever--nothing else comes close
Buy now direct from Lenovo
- LulzSec Says Goodbye with New Data Dump
- Hacker Collective Anonymous Strikes at Child Porn Sites
- Sony Admits Hackers Attacked Greek Unit
- AOL Revamps AIM with Facebook, Google Chat Apps
- Email, Personal Information on PlayBook Left Vulnerable to Hackers
- Porn Site Users Beware: LulzSec Posts Your E-mail Address
- Is Web 2.0 Safe?
- 12 Criteria for Selecting the Best ERP System Replacement An ERP system is your information backbone and reaches into all areas of your business and value chain. Replacing it can open unlimited business opportunities. This white paper explains the 12 criteria that allow you to identify and select the solution that will meet these expectations.
- Leveraging Social Computing Technologies for ERP Applications This white paper details how Web 2.0 technologies support business strategies by improving efficiency, productivity, and collaboration.




















