CVE-2005-1891: Integer Underflow
Published Jun 8, 2005
·Updated
The GIF parser in ateimg32.dll in AOL Instant Messenger (AIM) 5.9.3797 and earlier allows remote attackers to cause a denial of service (crash) via a malformed buddy icon that causes an integer underflow in a loop counter variable.
Affected Software
9 affected components
AOL Instant Messenger=5.0.2938
AOL Instant Messenger=5.1.3036
AOL Instant Messenger=5.2.3292
AOL Instant Messenger=5.5
AOL Instant Messenger=5.5.3415_beta
AOL Instant Messenger=5.5.3595
AOL Instant Messenger=5.9.3797
All of the following
AOL AIM<=5.9.3797
Microsoft Windows
Event History
Jun 8, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1891?
CVE-2005-1891 has a severity rating of medium due to its potential to cause a denial of service.
2
How do I fix CVE-2005-1891?
To fix CVE-2005-1891, upgrade AOL Instant Messenger to version 5.9.3798 or later.
3
What types of attacks are possible with CVE-2005-1891?
CVE-2005-1891 allows remote attackers to crash the application by sending a malformed buddy icon.
4
Which versions of AOL Instant Messenger are affected by CVE-2005-1891?
AOL Instant Messenger versions 5.9.3797 and earlier are affected by CVE-2005-1891.
5
Is CVE-2005-1891 specific to any operating systems?
CVE-2005-1891 affects AOL Instant Messenger on Microsoft Windows platforms.