CVE-2000-1094: Buffer Overflow
Published Jan 9, 2001
·Updated
Buffer overflow in AOL Instant Messenger (AIM) before 4.3.2229 allows remote attackers to execute arbitrary commands via a "buddyicon" command with a long "src" argument.
Affected Software
13 affected components
AOL AIM<4.3.2229
AOL Instant Messenger=4.0
AOL Instant Messenger=3.5.1856
AOL Instant Messenger=3.0_n
AOL Instant Messenger=4.1.2010
AOL Instant Messenger=3.5.1635
AOL Instant Messenger=2.0_n
AOL Instant Messenger=2.5.1598
AOL Instant Messenger=3.0.1470
AOL Instant Messenger=3.5.1808
AOL Instant Messenger=4.2.1193
AOL Instant Messenger=3.5.1670
AOL Instant Messenger=2.5.1366
Remediation
Event History
Jan 9, 2001
CVE Published
via NVD·05:00 AM
Jan 22, 2001
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-1094?
CVE-2000-1094 has a severity rating of medium due to its potential to allow remote code execution.
2
How do I fix CVE-2000-1094?
To fix CVE-2000-1094, upgrade AOL Instant Messenger to version 4.3.2229 or later.
3
What systems are affected by CVE-2000-1094?
CVE-2000-1094 affects various versions of AOL Instant Messenger up to 4.2.1193.
4
What type of vulnerability is CVE-2000-1094?
CVE-2000-1094 is a buffer overflow vulnerability that can be exploited via specially crafted commands.
5
Can CVE-2000-1094 be exploited remotely?
Yes, CVE-2000-1094 can be exploited remotely by attackers through the buddyicon command.