AOL You've Got Pictures SetAlbumName ActiveX Control Buffer Overflow Vulnerability
BID:20472
Info
AOL You've Got Pictures SetAlbumName ActiveX Control Buffer Overflow Vulnerability
| Bugtraq ID: | 20472 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-4840 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 11 2006 12:00AM |
| Updated: | Oct 12 2006 10:24PM |
| Credit: | The discoverer of this vulnerability wishes to remain anonymous. |
| Vulnerable: |
AOL Client Software 9.0 Security AOL Client Software 9.0 Optimized AOL Client Software 9.0 AOL Client Software 8.0 + AOL Client Software 8.0 |
| Not Vulnerable: | |
Discussion
AOL You've Got Pictures SetAlbumName ActiveX Control Buffer Overflow Vulnerability
AOL You've Got Pictures (YGP) Pic Downloader ActiveX control is prone to a buffer-overflow vulnerability because it fails to sufficiently bounds-check user-supplied data before copying it into a buffer.
Exploiting this issue may allow an attacker to execute arbitrary code in the context of the application that called the ActiveX control; this may facilitate further attacks.
AOL 9.0 Security Edition, 9.0, and prior versions are affected.
AOL You've Got Pictures (YGP) Pic Downloader ActiveX control is prone to a buffer-overflow vulnerability because it fails to sufficiently bounds-check user-supplied data before copying it into a buffer.
Exploiting this issue may allow an attacker to execute arbitrary code in the context of the application that called the ActiveX control; this may facilitate further attacks.
AOL 9.0 Security Edition, 9.0, and prior versions are affected.
Exploit / POC
AOL You've Got Pictures SetAlbumName ActiveX Control Buffer Overflow Vulnerability
Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
AOL You've Got Pictures SetAlbumName ActiveX Control Buffer Overflow Vulnerability
Solution:
AOL has released a fix to address this issue. Please see the referenced advisories for information on how to obtain and install the fix.
Solution:
AOL has released a fix to address this issue. Please see the referenced advisories for information on how to obtain and install the fix.
References
AOL You've Got Pictures SetAlbumName ActiveX Control Buffer Overflow Vulnerability
References:
References:
- AOL Home Page (AOL)
- iDefense Security Advisory 10.11.06: AOL YGPPDownload (iDefense Labs)