According to w00w00, the vulnerability arises from the way AIM handles a request to play a game. The attacker sends a malformed request to the target user, which causes a buffer overflow that enables the attacker to execute arbitrary code. W00w00 is warning that unless the vulnerability is fixed, it's quite possible all 100 million AIM users could be the target of a Code Red or Nimda-like worm that takes advantage of the application's weakness.
The group recommends that users go into their AIM preferences and in the Privacy section select the "Allow Only Users on My Buddy List" option under "Who can contact me."
Security firm Vigilinx Inc. is warning that the vulnerability could cause "heavy damage." The firm recommends that AIM users turn the software off until AOL provides a fix. Businesses are encouraged not to run AIM on their systems and to remove any previously installed versions.
AOL was not available for comment.
Stay connected and informed by visiting the CA Solutions Center Community!

Become a member today for instant access to free InformationWeek research, expert advice, peer perspectives, and more on the following topics:
- Application Performance Management (APM)
- Security Management
- Mainframe 2.0
- IT Automation
- Service Assurance
Also, visit our Government and Financial Services groups to see how these technologies apply specifically to those industries.
NOTE: Offer valid for U.S., U.S. possessions, & Canada only.