AOL scurries to fill AIM hole

C|Net | at | by Mike

AOL Time Warner on Wednesday pledged to close a security hole in its instant messenger application that experts say could provide wiggle room for a widespread and destructive worm. AOL Time Warner said it would implement a server-side fix--meaning people will not have to download the patch--by week's end. The security bug affects AOL Instant Messenger (AIM) version 4.7 and the 4.8 beta, or test version. Only AIM users running Microsoft's Windows operating system are vulnerable.

The advisory described the problem as a buffer overflow issue--one of the most common computer security glitches. The problem, which in this case affects AIM's game request function, occurs when an application crashes after being flooded with more code than it can accommodate. In a buffer overflow attack, maliciously written excess code can wind up being executed on the target computer.