Quantcast
PCWorld.com is upgrading some back-end systems. Some site features, such as user registration, may be temporarily unavailable.

AOL Confirms Security Hole in AIM

Flaw could leave PCs vulnerable to malicious code.

Sam Costello, IDG News Service

  • 0 Yes
  • 0 No

America Online admits there is a security hole in the latest versions of its AOL Instant Messenger (AIM) chat program, which corroborates findings an independent security group released Wednesday. AOL says it will fix the problem by the end of the week.

AOL has "identified the issue and developed a resolution that should be deployed in the next day or two," says Andrew Weinstein, spokesperson. The fix to the hole will take place on AOL's servers and will not require users to download patches, he says. AOL is unaware of the security problem actually impacting any users, he adds.

Buddy List Flaw

The hole, discovered by the security group W00w00, takes advantage of a flaw in the shared game features of AIM, Weinstein says. The vulnerable feature lets users invite members of their buddy list to participate in online games, but could let an attacker send malicious code to the victim's machine, w00w00 says in its advisory.

The security group also speculates that virus writers could use the bug to create a worm similar to the Code Red and Nimda worms that hit Microsoft's IIS (Internet Information Services) Web servers in July and October, respectively. In this scenario, the worm would attack vulnerable systems and spread via the buddy list on the infected PC, W00w00 says.

Helping Hand?

In a move that could potentially bring such a scenario into reality, W00w00 also posted code on its Web site that would let people use the hole for attacks. Posting full attack code follows full disclosure policy, which has been at the heart of a number of debates in the security community in recent months.

The vulnerability affects users of AIM versions 4.7 and 4.8, Weinstein says. W00w00 initially said the same thing, but later amended its findings in a post to the Bugtraq e-mail list saying that the problem impacts AIM versions as far back as 4.3.

However, AOL's Weinstein says that the only versions of the software that support the shared game feature where the vulnerability resides are versions 4.7 and 4.8.

Although Weinstein did not have exact numbers on hand, he says that AIM has more than 100 million registered users. No numbers were available as to how many users have the vulnerable versions of the software.

  • Recommend this story?
  • 0 Yes
    0 No
  • Great year-end deals
    for small business!
  • Get 24/7 live remote AT&T Tech Support 360* service along with select Lenovo* PCs (with Intel® Core™ 2 Duo processors) and save up to 200!

    Learn more

  • HP EliteBook* 6930p Notebook with Intel® vPro™ technology and a free HP Basic Docking Station - $641 instant savings!

    Learn more

Dell Laptop Deals

People who read this also read:

  • Perfect Printing Solutions Find just the right All-in-One printer for you from HP. Visit the HP Resource Center.
  • Lenovo Laptop Showcase Find out how Lenovo IdeaPads and Thinkpads balance performance and portability. Visit the Lenovo Resource Center for more info...

Sponsored Links