Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

CHAT:AIM:FILE-EXE

Severity

Low

Recommended

No

Category

CHAT

Keywords

Client File Receive Executable

Release Date

2005/08/16

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

AIM: Client File Receive Executable


This signature detects the transfer of executable files between AOL Instant Messenger (AIM) clients.

Extended Description

AOL Instant Messenger (AIM) is prone to an issue which may allow attackers to execute arbitrary files on the client system. It is possible to send a malicious link which references local files to a user of the client. When the link is visited, the referenced file on the client's local filesystem will be executed. To exploit this issue, the attacker must know the exact location of the file to be executed. Additionally, there can be no spaces in the path or filename. This limits exploitability, since files must be on the same partition and command line arguments cannot be supplied. Versions other than AOL Instant Messenger 4.8.2790 do not seem to be affected by this vulnerability. The vulnerability was reported for Microsoft Windows versions of the client.

Affected Products

  • AOL Instant Messenger 4.8.2790

References

  • BugTraq: 6027
  • CVE: CVE-2002-1813
  • URL: http://www.iss.net/security_center/static/10441.php
  • URL: http://www.kingant.net/oscar/

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out