TUCoPS :: Antique Systems :: aol3.htm

AOL - Crash AOL 4.0 with a picture background with a huge filename
Vulnerability

    aol

Affected

    AOL 4.0

Description

    The A-TEAM in  their first advisory  discovered following.   There
    is  a  big  security  problem  in  America OnLine 4.x which allows
    anybody to remotely crash AOL 4.x software by sending Email  which
    AOL  software  does  not  know  how  to  handle and thus causes an
    invalid page fault in module AOLRICH.AOL!  The exploit in  essence
    is  too  send  a  email  message  to  a America OnLine user with a
    [ background ] image that has a 255 character name.  This could be
    created in America OnLine's own Email message composer or  perhaps
    in a Email  program that allows  HTML formatting.   There might be
    potential for remote execution of unauthorized code.

    America OnLine 4.x  software does a  good job by  warning the user
    before  opening  the  Email  message  that  the  evil message sent
    contains a picture that could cause trouble for the reader.

Solution

    AOL should address this issue very soon.

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH