CVE-2001-1419: Medium severity AOL Instant Messenger vulnerability
Published Oct 2, 2001
·Updated
AOL Instant Messenger (AIM) 4.7.2480 and earlier allows remote attackers to cause a denial of service (application crash) via an instant message that contains a large amount of "<!--" HTML comments.
Affected Software
11 affected components
AOL Instant Messenger=4.0
AOL Instant Messenger=4.1
AOL Instant Messenger=4.2
AOL Instant Messenger=4.3
AOL Instant Messenger=4.3.2229
AOL Instant Messenger=4.4
AOL Instant Messenger=4.5
AOL Instant Messenger=4.6
AOL Instant Messenger=4.7
AOL Instant Messenger=4.7.2480
Cerulean Studios Trillian=0.6351
Event History
Oct 2, 2001
CVE Published
04:00 AM
Mar 20, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1419?
CVE-2001-1419 is classified as a denial of service vulnerability which can cause the application to crash.
2
How do I fix CVE-2001-1419?
To fix CVE-2001-1419, users should upgrade to AOL Instant Messenger version 4.7.2490 or later.
3
What versions of AOL Instant Messenger are affected by CVE-2001-1419?
CVE-2001-1419 affects AOL Instant Messenger versions 4.7.2480 and earlier.
4
Can CVE-2001-1419 be exploited remotely?
Yes, CVE-2001-1419 can be exploited remotely through an instant message containing HTML comments.
5
What impact does CVE-2001-1419 have on users?
The impact of CVE-2001-1419 is that it can lead to application crashes, resulting in potential service interruptions.