AOL Confirms Security Hole in AIM
Flaw could leave PCs vulnerable to malicious code.
Sam Costello, IDG News Service
America Online admits there is a security hole in the latest versions of its AOL Instant Messenger (AIM) chat program, which corroborates findings an independent security group released Wednesday. AOL says it will fix the problem by the end of the week.
AOL has "identified the issue and developed a resolution that should be deployed in the next day or two," says Andrew Weinstein, spokesperson. The fix to the hole will take place on AOL's servers and will not require users to download patches, he says. AOL is unaware of the security problem actually impacting any users, he adds.
Buddy List Flaw
The hole, discovered by the security group W00w00, takes advantage of a flaw in the shared game features of AIM, Weinstein says. The vulnerable feature lets users invite members of their buddy list to participate in online games, but could let an attacker send malicious code to the victim's machine, w00w00 says in its advisory.
The security group also speculates that virus writers could use the bug to create a worm similar to the Code Red and Nimda worms that hit Microsoft's IIS (Internet Information Services) Web servers in July and October, respectively. In this scenario, the worm would attack vulnerable systems and spread via the buddy list on the infected PC, W00w00 says.
Helping Hand?
In a move that could potentially bring such a scenario into reality, W00w00 also posted code on its Web site that would let people use the hole for attacks. Posting full attack code follows full disclosure policy, which has been at the heart of a number of debates in the security community in recent months.
The vulnerability affects users of AIM versions 4.7 and 4.8, Weinstein says. W00w00 initially said the same thing, but later amended its findings in a post to the Bugtraq e-mail list saying that the problem impacts AIM versions as far back as 4.3.
However, AOL's Weinstein says that the only versions of the software that support the shared game feature where the vulnerability resides are versions 4.7 and 4.8.
Although Weinstein did not have exact numbers on hand, he says that AIM has more than 100 million registered users. No numbers were available as to how many users have the vulnerable versions of the software.
The Best of PC World
Microsoft Office Home and Student 2007
Featured APC Accessories
-
APC Back-UPS ES
Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
- APC SurgeArrest Performance Highest level of protection for your professional computers, electronics and connected devices, as well as provides surge protection.
People who read this also read:
Best Prices on Security Software
Norton Internet Security 2010 - 3 UsersPrice: $27.90
Norton 360 Version 3Price: $38.98
Norton Internet Security 2010 - 3 UserPrice: $27.90
Internet Security 2010Price: $24.95
Internet Security 2010Price: $33.54
Internet Security 2009Price: $15.99
- 15 Minutes to a Secure Business Get the Secure in 15 toolkit starting with the "15 Minutes Month-at-a-Glance" calendar. McAfee will send you additional tools and tricks to stay protected around the clock.
- A Buyer's Guide to Data Protection Implementing data protection products and processes can be daunting. Make the right decisions by exploring what is available and what makes sense for your organization. Use this simple guide to evaluate different vendor offerings.
Cameras
Camcorders
Cell Phones
Components
Desktops
HDTV
Home Theater
GPS
Laptops
Monitors
MP3 Players
Networking &
Printers
Storage








