GraceNote CDDBControl ActiveX Control Remote Buffer Overflow Vulnerability
BID:18678
CVE-2006-3134 |Info
GraceNote CDDBControl ActiveX Control Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 18678 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-3134 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 27 2006 12:00AM |
| Updated: | Oct 20 2008 03:16PM |
| Credit: | Peter Vreugdenhi is credited with the discovery of this vulnerability. |
| Vulnerable: |
Sony SonicStage Mastering Studio 2.2.1 Sony SonicStage Mastering Studio 2.2 Sony SonicStage Mastering Studio 2.1.1 Sony SonicStage Mastering Studio 2.1 Sony SonicStage 3.4 Sony SonicStage 3.3 Sony CONNECT Player 0 Nokia PC Suite 6.8 Nokia PC Suite 6.7 Justsystem BeatJam 2006 GraceNote CDDBControl ActiveX 0 AOL Client Software 9.0 Security AOL Client Software 8.0 AOL Client Software 7.0 |
| Not Vulnerable: | |
Discussion
GraceNote CDDBControl ActiveX Control Remote Buffer Overflow Vulnerability
GraceNote CDDBControl ActiveX control is prone to a buffer-overflow vulnerability because the software fails to sufficiently bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Invoking the object from a malicious website or HTML email may trigger the condition. A successful exploit would corrupt process memory and allow arbitrary code to run in the context of the client application using the affected ActiveX control.
The following versions include the vulnerable software:
AOL 7.0 revision 4114.563
AOL 8.0 4129.230
AOL 9.0 Security Edition revision 4156.910
Other versions may also be affected.
GraceNote CDDBControl ActiveX control is prone to a buffer-overflow vulnerability because the software fails to sufficiently bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Invoking the object from a malicious website or HTML email may trigger the condition. A successful exploit would corrupt process memory and allow arbitrary code to run in the context of the client application using the affected ActiveX control.
The following versions include the vulnerable software:
AOL 7.0 revision 4114.563
AOL 8.0 4129.230
AOL 9.0 Security Edition revision 4156.910
Other versions may also be affected.
Exploit / POC
GraceNote CDDBControl ActiveX Control Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
GraceNote CDDBControl ActiveX Control Remote Buffer Overflow Vulnerability
Solution:
The vendor has released software updates to address this issue. Please contact the vendor for more information. See the references for details.
Fixes for affected AOL customers are available from the vendor through the AOL Client software's automatic update feature.
Sony SonicStage 3.3
Sony SonicStage 3.4
Sony CONNECT Player 0
Sony SonicStage Mastering Studio 2.1
Sony SonicStage Mastering Studio 2.1.1
Sony SonicStage Mastering Studio 2.2
Sony SonicStage Mastering Studio 2.2.1
Solution:
The vendor has released software updates to address this issue. Please contact the vendor for more information. See the references for details.
Fixes for affected AOL customers are available from the vendor through the AOL Client software's automatic update feature.
Sony SonicStage 3.3
-
GraceNote GracenoteUpdateForSony.exe
http://www.gracenote.com/sec062706/SonySecurityNotification.html
Sony SonicStage 3.4
-
GraceNote GracenoteUpdateForSony.exe
http://www.gracenote.com/sec062706/SonySecurityNotification.html
Sony CONNECT Player 0
-
GraceNote GracenoteUpdateForSony.exe
http://www.gracenote.com/sec062706/SonySecurityNotification.html
Sony SonicStage Mastering Studio 2.1
-
GraceNote GracenoteUpdateForSony.exe
http://www.gracenote.com/sec062706/SonySecurityNotification.html
Sony SonicStage Mastering Studio 2.1.1
-
GraceNote GracenoteUpdateForSony.exe
http://www.gracenote.com/sec062706/SonySecurityNotification.html
Sony SonicStage Mastering Studio 2.2
-
GraceNote GracenoteUpdateForSony.exe
http://www.gracenote.com/sec062706/SonySecurityNotification.html
Sony SonicStage Mastering Studio 2.2.1
-
GraceNote GracenoteUpdateForSony.exe
http://www.gracenote.com/sec062706/SonySecurityNotification.html
References
GraceNote CDDBControl ActiveX Control Remote Buffer Overflow Vulnerability
References:
References:
- AOL CDDBControl ActiveX Control "SetClientInfo()" Buffer Overflow (Secunia)
- AOL Homepage (AOL)
- GraceNote Homepage (GraceNote)
- GraceNote Security Update GraceNote (GraceNote)
- Gracenote Security Update June 27th, 2006 for BeatJam (GraceNote)
- Gracenote Sony Security Notification GraceNote (GraceNote)
- Nokia CDDBControl Security Advisory Nokia (Nokia)
- Nokia CDDBControl Software Update Nokia (Nokia)
- ZDI-06-019: GraceNote CDDBControl ActiveX Buffer Overflow Vulnerability (3Com Co (ZDI)