According to w00w00, the vulnerability arises from the way AIM handles a request to play a game. The attacker sends a malformed request to the target user, which causes a buffer overflow that enables the attacker to execute arbitrary code. W00w00 is warning that unless the vulnerability is fixed, it's quite possible all 100 million AIM users could be the target of a Code Red or Nimda-like worm that takes advantage of the application's weakness.
The group recommends that users go into their AIM preferences and in the Privacy section select the "Allow Only Users on My Buddy List" option under "Who can contact me."
Security firm Vigilinx Inc. is warning that the vulnerability could cause "heavy damage." The firm recommends that AIM users turn the software off until AOL provides a fix. Businesses are encouraged not to run AIM on their systems and to remove any previously installed versions.
AOL was not available for comment.More Software Insights
White Papers
Webcasts
Reports
Videos
BP seeking Regional Desktop Coordinator in Houston, TX
Agilent Technologies seeking Marketing Manager in Melbourne, AU
Advancement Project seeking Junior Web Developer in Los Angeles, CA
Johns Hopkins Univ Carey Business School seeking Asst Dean for IS in Baltimore, MD
City of Westland seeking MIS Director in Westland, MI
For more great jobs, career-related news, features and services, please visit our Career Center.
The Greening of IT - Saving Resources Helps the Environment and Cuts Costs
Virtualization, energy-efficient storage and multifunction devices all contribute to a more eco-friendly infrastructure. Hereŭs how your business can get greener and save money at the same time.
read more 
NOTE: Offer valid for U.S., U.S. possessions, & Canada only