AOL YGGPDownload DownloadFileDirectory ActiveX Controls Buffer Overflow Vulnerability
BID:20745
Info
AOL YGGPDownload DownloadFileDirectory ActiveX Controls Buffer Overflow Vulnerability
| Bugtraq ID: | 20745 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-5501 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 25 2006 12:00AM |
| Updated: | Oct 26 2006 09:03PM |
| Credit: | The discoverer of this vulnerability wishes to remain anonymous. |
| Vulnerable: |
AOL Client Software 9.0 Security |
| Not Vulnerable: | |
Discussion
AOL YGGPDownload DownloadFileDirectory ActiveX Controls Buffer Overflow Vulnerability
AOL YGPPDownload downloadFileDirectory ActiveX control is prone to a heap-based buffer-overflow vulnerability.
An attacker can invoke the object from a malicious web page to trigger the condition. If the vulnerability is successfully exploited, this would result in a denial-of-service condition due to a runtime error in the affected module that crashes the running instance of the client application that the object is invoked through (typically Internet Explorer). An attacker may also be able to exploit the condition to corrupt process memory, resulting in arbitrary code execution with the privileges of the currently logged-in user.
AOL YGPPDownload downloadFileDirectory ActiveX control is prone to a heap-based buffer-overflow vulnerability.
An attacker can invoke the object from a malicious web page to trigger the condition. If the vulnerability is successfully exploited, this would result in a denial-of-service condition due to a runtime error in the affected module that crashes the running instance of the client application that the object is invoked through (typically Internet Explorer). An attacker may also be able to exploit the condition to corrupt process memory, resulting in arbitrary code execution with the privileges of the currently logged-in user.
Exploit / POC
AOL YGGPDownload DownloadFileDirectory ActiveX Controls Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
AOL YGGPDownload DownloadFileDirectory ActiveX Controls Buffer Overflow Vulnerability
Solution:
Fixes are available from the vendor through the AOL Client software's automatic update feature.
Solution:
Fixes are available from the vendor through the AOL Client software's automatic update feature.
References
AOL YGGPDownload DownloadFileDirectory ActiveX Controls Buffer Overflow Vulnerability
References:
References:
- AOL Home Page (AOL)