iEntry 10th Anniversary RSS Archive

IT Management Begins With Security
SecurityProNews > Insider Reports > Insider > ICQ, AIM Flaw Poses File Transfer Trouble
Search:
[ insider_reports_insider ]

ICQ, AIM Flaw Poses File Transfer Trouble



David Utter
Staff Writer
2007-04-10

SecurityProNews: Insider Reports Insider Reports RSS Feed


People who use AIM or ICQ for instant messaging are vulnerable to a file transfer path traversal vulnerability that could be remotely exploited.

ICQ, AIM Flaw Poses File Transfer Trouble
ICQ, AIM Flaw Poses File Transfer Trouble

Those who would rather not have someone out there dropping files on their systems over AIM or ICQ have different options available to them right now.

An iDefense Labs report said that fixes to AIM's infrastructure will mitigate the problem for AIM version 5.9 and earlier, although AIM's parent AOL suggests people upgrade AIM to a current version.

For ICQ, AOL pushed out an automatic update that patched the flaw, which was present in ICQ 5.1 and was likely present in previous versions.

Problems could have come during a file transfer session while using one of those vulnerable clients.

Attackers would be able to place arbitrarily named files in a directory of their choice when the victim accepts a file transfer.

In ICQ, a user has to have the attacker on a buddy list, and also manually accept the requested transfer. This served to limit the threat to ICQ clients.

Microsoft Thinks Security Is Funny: Zombies, ninjas, aliens, and overdressed superspies threaten the diligent, bespectacled IT guy in Microsoft's newest ad campaign pushing their Forefront business security products.

The campaign at Easy, Easier presents a humorous informational approach to learning about Microsoft's options in the computer security industry.

Our thoughts? The zombie looks like the bizarre love child of Don Imus and Mick Jagger.

---

AddThis Social Bookmark Button


Tags: , , , ,



About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.

More insider_reports_insider Articles

SecurityProNews: Insider Reports Insider Reports RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com

Titan Quest Forum
The #1 Titan Quest forum
Halo 3 Forum
The best Halo, Halo 2, Halo 3 forum
Nintendo Wii
Nintendo Wii news and views
Mac Software
The best in OS X freeware
Graphics Forum
Your source for graphic tutorials
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds