PT-2006-4739 · Aol · America Online

Will Dormann

·

Publicado

2006-10-10

·

Atualizado

2017-07-20

·

CVE-2006-3888

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions America Online version 9.0 Security Edition
Description A buffer overflow issue exists in the AOL You've Got Pictures (YGP) Pic Downloader YGPPDownload ActiveX control, which can be exploited by remote attackers to execute arbitrary code. This is achieved by passing a long argument to the SetAlbumName method.
Recommendations For America Online version 9.0 Security Edition, consider disabling the YGPPDownload ActiveX control until a patch is available. Restrict access to the SetAlbumName method to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-3888

Produtos afetados

America Online