First published: Wed Jun 08 2005(Updated: )
The GIF parser in ateimg32.dll in AOL Instant Messenger (AIM) 5.9.3797 and earlier allows remote attackers to cause a denial of service (crash) via a malformed buddy icon that causes an integer underflow in a loop counter variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AOL | =5.0.2938 | |
AOL | =5.1.3036 | |
AOL | =5.2.3292 | |
AOL | =5.5 | |
AOL | =5.5.3415_beta | |
AOL | =5.5.3595 | |
AOL | =5.9.3797 | |
All of | ||
AOL Instant Messenger Lite | <=5.9.3797 | |
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1891 has a severity rating of medium due to its potential to cause a denial of service.
To fix CVE-2005-1891, upgrade AOL Instant Messenger to version 5.9.3798 or later.
CVE-2005-1891 allows remote attackers to crash the application by sending a malformed buddy icon.
AOL Instant Messenger versions 5.9.3797 and earlier are affected by CVE-2005-1891.
CVE-2005-1891 affects AOL Instant Messenger on Microsoft Windows platforms.