First published: Mon Apr 08 2002(Updated: )
AOL Instant Messenger (AIM) 4.7.2480 adds free.aol.com to the Trusted Sites Zone in Internet Explorer without user approval, which could allow code from free.aol.com to bypass intended access restrictions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AOL AIM Triton | =4.7.2480 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2002-1591 is considered to be moderate, as it allows unauthorized access to resources by adding a site to the Trusted Sites Zone without user consent.
To fix CVE-2002-1591, you should review and remove free.aol.com from the Trusted Sites Zone in Internet Explorer settings.
CVE-2002-1591 affects AOL Instant Messenger version 4.7.2480.
CVE-2002-1591 allows malicious code from free.aol.com to bypass security restrictions, potentially compromising the user's system.
A temporary workaround for CVE-2002-1591 is to manually adjust your Internet Explorer Trusted Sites settings to remove any unwanted sites.