PT-2006-7051 · Aol · Cddbcontrolaol.Cddbaolcontrol
Published
2006-12-10
·
Updated
2018-10-17
·
CVE-2006-6442
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
CDDBControlAOL.CDDBAOLControl ActiveX control versions in America Online (AOL) 7.0 4114.563 through 9.0 Security Edition 4156.910
Description
The issue is a stack-based buffer overflow in the
SetClientInfo function, allowing remote attackers to execute arbitrary code via a long ClientId argument.Recommendations
For versions 7.0 4114.563 through 9.0 Security Edition 4156.910, consider disabling the
SetClientInfo function until a patch is available.
Restrict access to the cddbcontrol.dll module to minimize the risk of exploitation.
Avoid using the ClientId argument in the affected ActiveX control until the issue is resolved.Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cddbcontrolaol.Cddbaolcontrol