BigAnt IM Server contains an overflow condition in the AntDS.exe file. The issue is triggered as user-supplied input is not properly validated when handling the filename header in SCH requests or when handling the userid component in DUPF requests. With a specially crafted request, a remote attacker can cause a stack-based buffer overflow, resulting in a denial of service or potentially execution of arbitrary code.