PT-2006-4739 · Aol · America Online
Will Dormann
·
Publicado
2006-10-10
·
Atualizado
2017-07-20
·
CVE-2006-3888
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
America Online version 9.0 Security Edition
Description
A buffer overflow issue exists in the AOL You've Got Pictures (YGP) Pic Downloader YGPPDownload ActiveX control, which can be exploited by remote attackers to execute arbitrary code. This is achieved by passing a long argument to the
SetAlbumName method.Recommendations
For America Online version 9.0 Security Edition, consider disabling the YGPPDownload ActiveX control until a patch is available. Restrict access to the
SetAlbumName method to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
America Online