CVE-2000-0383: Medium severity AOL Instant Messenger vulnerability

Published May 8, 2000
·
Updated

The file transfer component of AOL Instant Messenger (AIM) reveals the physical path of the transferred file to the remote recipient.

Affected Software

1 affected component
AOL Instant Messenger=4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Disable AIM's file transfer feature to prevent the remote recipient from seeing the physical path of transferred files.

    AOL Instant Messenger (AIM) file transfer component file transfer = disabled
  2. Compensating control

    Avoid sending files over AIM; restrict or block AIM file transfers at network or endpoint controls and use a different secure file transfer method to prevent disclosure of local filesystem paths.

  3. Operational

    Notify users and administrators that AIM's file transfer reveals physical file paths and instruct them not to send files that could expose sensitive filesystem information until a vendor-supplied fix is available.

Event History

May 8, 2000
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Jun 15, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2000-0383?

CVE-2000-0383 is classified as a medium severity vulnerability due to the potential exposure of sensitive file paths.

2

How do I fix CVE-2000-0383?

Fixing CVE-2000-0383 involves upgrading to a later version of AOL Instant Messenger that addresses this vulnerability.

3

What impact does CVE-2000-0383 have on users?

CVE-2000-0383 can lead to unauthorized disclosure of file paths to remote recipients during file transfers.

4

Which versions of AOL Instant Messenger are affected by CVE-2000-0383?

AOL Instant Messenger version 4.0 is the only version affected by CVE-2000-0383.

5

Is CVE-2000-0383 exploitable?

Yes, CVE-2000-0383 is exploitable as it allows attackers to gain insights into file structures via revealed paths.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203