PT-2006-7051 · Aol · Cddbcontrolaol.Cddbaolcontrol
Publicado
2006-12-10
·
Atualizado
2018-10-17
·
CVE-2006-6442
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
CDDBControlAOL.CDDBAOLControl ActiveX control versions in America Online (AOL) 7.0 4114.563 through 9.0 Security Edition 4156.910
Description
The issue is a stack-based buffer overflow in the
SetClientInfo function, allowing remote attackers to execute arbitrary code via a long ClientId argument.Recommendations
For versions 7.0 4114.563 through 9.0 Security Edition 4156.910, consider disabling the
SetClientInfo function until a patch is available.
Restrict access to the cddbcontrol.dll module to minimize the risk of exploitation.
Avoid using the ClientId argument in the affected ActiveX control until the issue is resolved.Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cddbcontrolaol.Cddbaolcontrol