CVE-2006-6442
Summary
| CVE | CVE-2006-6442 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-12-10 11:28:00 UTC |
| Updated | 2018-10-17 21:48:00 UTC |
| Description | Stack-based buffer overflow in the SetClientInfo function in the CDDBControlAOL.CDDBAOLControl ActiveX control (cddbcontrol.dll), as used in America Online (AOL) 7.0 4114.563, 8.0 4129.230, and 9.0 Security Edition 4156.910, and possibly other products, allows remote attackers to execute arbitrary code via a long ClientId argument. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Aol | Aol Client Software | 7.0_4114.563 | All | All | All |
| Application | Aol | Aol Client Software | 8.0_4129.230 | All | All | All |
| Application | Aol | Aol Client Software | 9.0 | All | security_4156.910 | All |
| Application | Aol | Aol Client Software | 7.0_4114.563 | All | All | All |
| Application | Aol | Aol Client Software | 8.0_4129.230 | All | All | All |
| Application | Aol | Aol Client Software | 9.0 | All | security_4156.910 | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| AOL Buffer Overflow in CDDBControl ActiveX Control Lets Remote Users Execute Arbitrary Code - SecurityTracker | SECTRACK | securitytracker.com | |
| [Full-disclosure] Secunia Research: AOL CDDBControl ActiveX Control "SetClientInfo()" Buffer Overflow | FULLDISC | lists.grok.org.uk | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| AOL CDDBControl ActiveX Control "SetClientInfo()" Buffer Overflow - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| RETIRED: AOL CDDBControl ActiveX Control Buffer Overflow Vulnerability | BID | www.securityfocus.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| AOL CDDBControl ActiveX Control "SetClientInfo()" Buffer Overflow - Secunia Research - Secunia | MISC | secunia.com | Vendor Advisory |
| [VIM] GraceNote CDDBControl (CVE-2006-3134) = CDDBAOLControl (CVE-2006-6442) | VIM | attrition.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.