|
AOL Instant Messenger Link Special Character Remote Heap Overflow Vulnerability
The following procedure has been reported by a b <p0pt4rtz@hotmail.com> as producing a denial of service: Craft the URL to be sent to the victim. Lets use spaces since they get converted to %20 by AIM :). We could use other extended ASCII, etc. Fill the whole URL up to the end (the "protected" buffer dist), which is 172 chars. (172 * 2 = 344). |
|
|
Privacy Statement |