PT-2006-6216 · Aol · Aol.Picdownloadctrl.1 Activex Control+1

Publicado

2006-10-25

·

Atualizado

2017-07-20

·

CVE-2006-5501

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions America Online (AOL) version 9.0 Security Edition AOL.PicDownloadCtrl.1 ActiveX control (YGPPicDownload.dll) version 9.2.3.0
Description The issue is a buffer overflow in the AOL.PicDownloadCtrl.1 ActiveX control, which allows remote attackers to execute arbitrary code via the downloadFileDirectory property.
Recommendations For America Online (AOL) version 9.0 Security Edition, consider disabling the downloadFileDirectory property in the AOL.PicDownloadCtrl.1 ActiveX control until a patch is available. For AOL.PicDownloadCtrl.1 ActiveX control (YGPPicDownload.dll) version 9.2.3.0, restrict access to the control to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-5501

Produtos afetados

Aol.Picdownloadctrl.1 Activex Control
America Online