× The internal search function is temporarily non-functional. The current search engine is no longer viable and we are researching alternatives.
As a stop gap measure, we are using Google's custom search engine service.
If you know of an easy to use, open source, search engine ... please contact support@midrange.com.


  • Subject: Re: blocking ports
  • From: "Jim Franz" <franz400@xxxxxxxxxxxx>
  • Date: Wed, 21 Mar 2001 18:56:28 -0500

several from www.sans.org
Advisory ...multiple buffer overflows ...AOL Instant Messenger ...a malicious Web site or e-mail to execute arbitrary code on a user's system.
AOL Instant Messenger v3.5.1856 contains buffer overflow that leads to the crashing of the client;
Advisory and exploit that details a bug in the Messenger/winpopup service in Windows 95/98 has been published. The denial of service causes the whole system to become unstable and sometimes even immediately reboot.
A report has surfaced indicating a potential problem in AOL Instant Messenger (versions 4.1 through 4.4). Due to the way AIM logs data, it is possible for a malicious user to send a malformed image embedded in a conversation. While this won't affect the current conversation, it may alter the log files in such a way that would cause JavaScript/VBScript to be executed when the user views logs of the conversation
 
When initiated, it can be a 2-way "trusted" path, thru your firewall (you do have one?).
jim
----- Original Message -----
From: M. Lazarus
Sent: Wednesday, March 21, 2001 10:49 PM
Subject: Re: blocking ports

Angie,

At 3/21/01 12:21 PM -0500, you wrote:
The instant messengers that come with many browsers like AOL create a security problem. 

 What is the problem?

 -mark

As an Amazon Associate we earn from qualifying purchases.

This thread ...

Replies:

Follow On AppleNews
Return to Archive home page | Return to MIDRANGE.COM home page

This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].

Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.