iDefense Security Advisory 04.09.07 – Remote exploitation of a path-traversal vulnerability in AOL’s AIM and ICQ could allow a remote attacker to place arbitrary files on the victim’s machine during a file transfer operation. AIM and ICQ allow users to share and transfer files via a custom protocol. During file transfers, the sender is allowed to specify the display name of the file, and the filename used for the transfer. The recipient can only specify the folder in which to save the file. Due to an input validation flaw, the clients do not properly strip “../” traversal characters from the filename the attacker supplies. By specially encoding the path attackers can force the file to be saved to a directory of their choosing when the victim accepts the file transfer. iDefense has confirmed this vulnerability in ICQ version 5.1. Previous versions are suspected vulnerable. Additionally, AOL reported that AIM version 5.9 and prior are vulnerable.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/55789/04.09.07-1.txt
Source: https://packetstormsecurity.com/files/55789/iDEFENSE-Security-Advisory-2007-04-09.1.html

