Posted by Virus Bulletin on Nov 9, 2006
Chat program remote execution flaw patched.
Details of a vulnerability found in AOL's ICQ instant messaging software have been released by TippingPoint. The ActiveX flaw could allow unpatched versions of the software to be targeted and exploited remotely with no user interaction.
The bug was first reported to AOL in late September, and the details are being made public a week after a fix was developed and released to users. Anyone who has logged on to the AOL network since the patch release should have been automatically updated, but as the vulnerability can break into a machine just by sending a chat message, some users are thought to remain at risk and are advised to update their software.
Information on the vulnerability and the patch can be found at TippingPoint's Zero Day Initiative site, here, or at Secunia, here.
Posted on 09 November 2006 by Virus Bulletin