PT-2008-1660 · Aol · Aol You'Ve Got Pictures
Publicado
2008-02-04
·
Atualizado
2008-11-15
·
CVE-2007-6699
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
AOL You've Got Pictures (YGP) Picture Editor version 9.5.1.8
Description
The issue concerns multiple buffer overflows in the AIM PicEditor ActiveX control. These overflows can be triggered by a long string in various property values, including
DisplayName, FinalSavePath, ForceSaveTo, HiddenControls, InitialEditorScreen, Locale, Proxy, and UserAgent. This can cause a denial of service, resulting in a browser crash.Recommendations
For version 9.5.1.8, consider restricting the input length for the
DisplayName, FinalSavePath, ForceSaveTo, HiddenControls, InitialEditorScreen, Locale, Proxy, and UserAgent properties to prevent buffer overflows. As a temporary workaround, avoid using long strings in these property values until a patch is available.Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Aol You'Ve Got Pictures