AOL 9.0 Deskbar.dll/Toolbar.dll DoS Vulnerability



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Overview

AOL has recently been made aware of a denial of service condition that
exists in early versions of the AOL 9.0 client software. The affected
DLLs are listed below:

* Deskbar.dll
* Toolbar.dll

AOL does not believe that the issue presents a threat to a user's system
or data. If a user were to access a website that had specially crafted
code intended to exploit the bug, the result would be a crash of the
user's browser.


Affected Products and Applications

* AOL 9.0 (released prior to February 2007)

Solutions

1. Users of an affected client are encouraged to upgrade to the latest
version of the AOL client available from http://www.aol.com/.


Acknowledgments

AOL would like to thank Justin Seitz for his assistance in identifying and
responsibly reporting this issue.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (Darwin)

iD8DBQFGC/jqmtUUpo0iUmgRAh7JAKDbHXXD0DO5OQy95ZlEAzKPZRCxegCdFc5m
1dHjBd8CyeeXXx8IIwXSs1Y=
=23oS
-----END PGP SIGNATURE-----



Relevant Pages

  • Re: ISA 2004 and AOL 9 wont work right...
    ... They can get their AOL email via the aol website mail client - I wouldn't ... Proxy 2.0 (and now ISA) plays quite nicely with pretty much every other ... down to the client computers and reconfigured ISA Internet Access Rule ...
    (microsoft.public.windows.server.sbs)
  • RE: ISA 2004 stops AOL web usage
    ... client on all the client computers, we may have to temporarily disable it ... when you want to use AOL because there is something incompatible with ISA ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • Re: ISA 2004 and AOL 9 wont work right...
    ... They can get their mail via aol.com They don't need the AOL client. ... I have a client that has ISA Server 2004 on SBS 2003 Premium. ... was configured with the SBS Internet Access Rule to allow All Users to ...
    (microsoft.public.windows.server.sbs)
  • Re: ISA 2004 and AOL 9 wont work right...
    ... trying to get a client working, and the only help I got from AOL was to ... Proxy 2.0 (and now ISA) plays quite nicely with pretty much every other app ... sane thing of telling your clients you will not support AOL in a business ... down to the client computers and reconfigured ISA Internet Access Rule ...
    (microsoft.public.windows.server.sbs)
  • Re: Security for stand alone computer.
    ... Which ISP do you use that uses the client for Microsoft networks? ... The AOL Dialup Adapter and AOL Adapter are created ...
    (comp.security.firewalls)