First published: Tue Apr 10 2007(Updated: )
Directory traversal vulnerability in AOL Instant Messenger (AIM) 5.9 and earlier, and ICQ 5.1 and probably earlier, allows user-assisted remote attackers to write files to arbitrary locations via a .. (dot dot) in a filename in a file transfer operation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ICQ | <=5.1 | |
AOL Instant Messenger | <=5.9.3861 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1904 is classified as a medium severity vulnerability due to its potential for exploitation in a user-assisted context.
To mitigate CVE-2007-1904, users should upgrade to the latest versions of AOL Instant Messenger or ICQ that are not affected by this vulnerability.
CVE-2007-1904 affects AOL Instant Messenger versions up to 5.9 and ICQ versions up to 5.1.
CVE-2007-1904 allows remote attackers to exploit directory traversal to write files to arbitrary locations on a victim's system.
Yes, CVE-2007-1904 requires user assistance, meaning that the attack typically requires the victim to perform actions that facilitate the exploitation.