AOL Instant Messenger prior to v5.5.3415 contains a buffer overflow in the CCertsByUserName::Cleanup() function which can lead to remote code execution. Can be exploited via HTML web pages or email via long aim: URIs. Fix available here.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/31868/aim.v5-overflow.txt
Source: https://packetstormsecurity.com/files/31868/aim.v5-overflow.txt.html

