AOL didn't patch AIM holes, users exposed
C|Net | at | by Mike
AOL Time Warner failed to properly fix a security hole in its AOL Instant Messenger application, leaving its users vulnerable to a new way to exploit the same flaw, a security researcher said this weekend. The glitch's latest incarnation could have been just as dangerous as the previous version, publicized in January, opening the way for malicious AIM users to execute any program on a vulnerable user's computer, said Matt Conover, a hacker with a security research group known as "w00w00."
"This is almost identical to the problem we found originally, and that's saddening," he said. "By using a slightly different method, we are able to get around the filtering they used to protect against the last flaw."