AOL Radio 'MediaPlaybackControl.exe' AmpX ActiveX Control Stack Buffer Overflow Vulnerability
BID:27207
Info
AOL Radio 'MediaPlaybackControl.exe' AmpX ActiveX Control Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 27207 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-6250 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 09 2008 12:00AM |
| Updated: | Jan 11 2008 01:59AM |
| Credit: | Will Dorman of CERT/CC is credited with the discovery of this vulnerability. |
| Vulnerable: |
AOL Radio 0 AOL AmpX.dll 2.6.1.11 |
| Not Vulnerable: |
AOL AmpX.dll 2.6.2.6 |
Discussion
AOL Radio 'MediaPlaybackControl.exe' AmpX ActiveX Control Stack Buffer Overflow Vulnerability
AOL Radio AmpX ActiveX control is prone to a stack-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Invoking the object from a malicious website or HTML email may trigger the condition. A successful attack would corrupt process memory, allowing arbitrary code to run in the context of the client application using the affected ActiveX control.
This issue affects versions prior to 'AmpX.dll' 2.6.2.6.
AOL Radio AmpX ActiveX control is prone to a stack-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Invoking the object from a malicious website or HTML email may trigger the condition. A successful attack would corrupt process memory, allowing arbitrary code to run in the context of the client application using the affected ActiveX control.
This issue affects versions prior to 'AmpX.dll' 2.6.2.6.
Exploit / POC
AOL Radio 'MediaPlaybackControl.exe' AmpX ActiveX Control Stack Buffer Overflow Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
AOL Radio 'MediaPlaybackControl.exe' AmpX ActiveX Control Stack Buffer Overflow Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
AOL Radio 'MediaPlaybackControl.exe' AmpX ActiveX Control Stack Buffer Overflow Vulnerability
References:
References:
- AOL Radio Homepage (AOL)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Vulnerability Note VU#568681 (US-CERT)