PT-2006-6216 · Aol · Aol.Picdownloadctrl.1 Activex Control+1

Published

2006-10-25

·

Updated

2017-07-20

·

CVE-2006-5501

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions America Online (AOL) version 9.0 Security Edition AOL.PicDownloadCtrl.1 ActiveX control (YGPPicDownload.dll) version 9.2.3.0
Description The issue is a buffer overflow in the AOL.PicDownloadCtrl.1 ActiveX control, which allows remote attackers to execute arbitrary code via the downloadFileDirectory property.
Recommendations For America Online (AOL) version 9.0 Security Edition, consider disabling the downloadFileDirectory property in the AOL.PicDownloadCtrl.1 ActiveX control until a patch is available. For AOL.PicDownloadCtrl.1 ActiveX control (YGPPicDownload.dll) version 9.2.3.0, restrict access to the control to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-5501

Affected Products

Aol.Picdownloadctrl.1 Activex Control
America Online