CVE-2001-1417: Medium severity AOL Instant Messenger vulnerability
Published Oct 6, 2001
·Updated
AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application hang or crash) via a buddy icon GIF file whose length and width values are larger than the actual image data.
Affected Software
1 affected component
AOL Instant Messenger=4.7
Event History
Oct 6, 2001
CVE Published
04:00 AM
Mar 20, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1417?
CVE-2001-1417 has a severity rating classified as a denial of service vulnerability.
2
How do I fix CVE-2001-1417?
To fix CVE-2001-1417, upgrade to a later version of AOL Instant Messenger beyond 4.7.
3
What systems are vulnerable to CVE-2001-1417?
CVE-2001-1417 affects AOL Instant Messenger version 4.7.
4
What type of attack does CVE-2001-1417 allow?
CVE-2001-1417 allows attackers to cause application hangs or crashes through specially crafted buddy icons.
5
Is CVE-2001-1417 still relevant today?
While the specific vulnerability may no longer be exploitative due to the age of AOL Instant Messenger, it highlights important security lessons in handling input data.