Re: AOL IM 4.7 d0s 0-Day

From: Matthew Sachs (matthewg@zevils.com)
Date: 10/01/01


Date: Mon, 1 Oct 2001 02:01:53 -0400
From: Matthew Sachs <matthewg@zevils.com>
To: vuln-dev@securityfocus.com
Subject: Re: AOL IM 4.7 d0s 0-Day
Message-ID: <20011001020153.A28822@allevil.dhcp.zevils.com>

I just saw this with my custom AIM client. It's an IM consisting of
a repeated sequence of "<!-- " (sans quotes). I tested it against
WinAIM 4.7.2480 and it does indeed produce the crash you described.

-- 
Matthew Sachs, the original nonstandard deviant
matthewg@zevils.com	http://www.zevils.com/
GPG key: 0x600A0342	PGP key: 0x93EA1151


Quantcast