CVE-2004-2373: High severity AOL Instant Messenger vulnerability
Published Dec 31, 2004
·Updated
The Buddy icon file for AOL Instant Messenger (AIM) 4.3 through 5.5 is created in a predictable location, which may allow remote attackers to use a shell: URI to exploit other vulnerabilities that involve predictable locations.
Affected Software
15 affected components
AOL Instant Messenger=5.0.2938
AOL Instant Messenger=4.8.2646
AOL Instant Messenger=4.5
AOL Instant Messenger=4.3
AOL Instant Messenger=4.6
AOL Instant Messenger=5.5
AOL Instant Messenger=4.3.2229
AOL Instant Messenger=4.8.2616
AOL Instant Messenger=5.1.3036
AOL Instant Messenger=4.7
AOL Instant Messenger=5.2.3292
AOL Instant Messenger=4.7.2480
AOL Instant Messenger=4.8.2790
AOL Instant Messenger=4.4
AOL Instant Messenger=5.5.3415_beta
Event History
Dec 31, 2004
CVE Published
05:00 AM
Aug 16, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2373?
CVE-2004-2373 is classified as a medium severity vulnerability.
2
What versions of AOL Instant Messenger are affected by CVE-2004-2373?
CVE-2004-2373 affects AOL Instant Messenger versions 4.3 through 5.5.
3
How do I fix CVE-2004-2373?
To fix CVE-2004-2373, upgrade AOL Instant Messenger to a version later than 5.5.
4
What type of attack does CVE-2004-2373 allow?
CVE-2004-2373 can allow remote attackers to exploit other vulnerabilities by leveraging predictable file locations.
5
Is there a patch available for CVE-2004-2373?
No specific patch is mentioned for CVE-2004-2373, but the vendor recommends upgrading to a non-vulnerable version.