Users login

Create an account »

JOIN XATRIX

Users login

Home » Hacking News » AOL warns of ICQ attack risk

AOL warns of ICQ attack risk

by Nikola Strahija on January 20th, 2002 People chatting with outdated ICQ software are at risk for a potentially damaging buffer overflow exploit, AOL TThe buffer overflow vulnerability affects versions of America Online's popular ICQ instant messaging software prior to version 2001b, which was released October. Only versions for Microsoft's Windows operating system are vulnerable.


AOL posted a page urging people who haven't already downloaded the latest version of ICQ software to do so.

"We are encouraging people to upgrade," AOL representative Andrew Weinstein said. "And we are taking additional server-side precautions. But we do not believe this vulnerability has ever been exploited."


It is the second buffer overflow vulnerability to surface in AOL's instant messaging software since the beginning of the year.

The first, in AOL Instant Messenger (AIM), affected Microsoft Windows-compatible versions 4.7 and 4.8 beta.

The holes have surfaced as security analysts are giving IM applications new scrutiny. Although virus and worm authors have thus far concentrated on e-mail as a means of propagation, the rising popularity of instant messaging has made the technology an increasingly attractive target.

Buffer overflows are among the most common computer security glitches. They crop up when an application crashes after being flooded with more code than it can accommodate. In a buffer overflow attack, maliciously written excess code can wind up being executed on the target computer.

"Worse case scenario is that if someone sent you a message, and you click on it, it would be possible to execute arbitrary code," Tan said in an interview. "They could pretty much do anything they wanted."

Among the problems associated with buffer overflow vulnerabilities are self-propagating worms of the type seen in the destructive Melissa, I Love You, Code Red and Nimda infestations.


Newsletter signup

Signup to our monthly newsletter and stay in touch with IT news!

Free E-books

We've got ebooks! But they're not online. :( Please give us a few days to bring downloads back.

Contact

Have something to say or just wanna drop us a line? Please keep this in mind: to spam, we reply with spam.

Contact us »