Quantcast
PCWorld.com is upgrading some back-end systems. Some site features, such as user registration, may be temporarily unavailable.

AOL Confirms Security Hole in AIM

Flaw could leave PCs vulnerable to malicious code.

Sam Costello, IDG News Service

  • 0 Yes
  • 0 No

America Online admits there is a security hole in the latest versions of its AOL Instant Messenger (AIM) chat program, which corroborates findings an independent security group released Wednesday. AOL says it will fix the problem by the end of the week.

AOL has "identified the issue and developed a resolution that should be deployed in the next day or two," says Andrew Weinstein, spokesperson. The fix to the hole will take place on AOL's servers and will not require users to download patches, he says. AOL is unaware of the security problem actually impacting any users, he adds.

Buddy List Flaw

The hole, discovered by the security group W00w00, takes advantage of a flaw in the shared game features of AIM, Weinstein says. The vulnerable feature lets users invite members of their buddy list to participate in online games, but could let an attacker send malicious code to the victim's machine, w00w00 says in its advisory.

The security group also speculates that virus writers could use the bug to create a worm similar to the Code Red and Nimda worms that hit Microsoft's IIS (Internet Information Services) Web servers in July and October, respectively. In this scenario, the worm would attack vulnerable systems and spread via the buddy list on the infected PC, W00w00 says.

Helping Hand?

In a move that could potentially bring such a scenario into reality, W00w00 also posted code on its Web site that would let people use the hole for attacks. Posting full attack code follows full disclosure policy, which has been at the heart of a number of debates in the security community in recent months.

The vulnerability affects users of AIM versions 4.7 and 4.8, Weinstein says. W00w00 initially said the same thing, but later amended its findings in a post to the Bugtraq e-mail list saying that the problem impacts AIM versions as far back as 4.3.

However, AOL's Weinstein says that the only versions of the software that support the shared game feature where the vulnerability resides are versions 4.7 and 4.8.

Although Weinstein did not have exact numbers on hand, he says that AIM has more than 100 million registered users. No numbers were available as to how many users have the vulnerable versions of the software.

  • Recommend this story?
  • 0 Yes
    0 No
 

Featured APC Accessories

  • APC Back-UPS ES Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
  • APC SurgeArrest Performance Highest level of protection for your professional computers, electronics and connected devices, as well as provides surge protection.

People who read this also read:

  • 15 Minutes to a Secure Business Get the Secure in 15 toolkit starting with the "15 Minutes Month-at-a-Glance" calendar. McAfee will send you additional tools and tricks to stay protected around the clock.
  • A Buyer's Guide to Data Protection Implementing data protection products and processes can be daunting. Make the right decisions by exploring what is available and what makes sense for your organization. Use this simple guide to evaluate different vendor offerings.

Sponsored Links