Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

GraceNote CDDBControl ActiveX Control Remote Buffer Overflow Vulnerability

GraceNote CDDBControl ActiveX control is prone to a buffer-overflow vulnerability because the software fails to sufficiently bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

Invoking the object from a malicious website or HTML email may trigger the condition. A successful exploit would corrupt process memory and allow arbitrary code to run in the context of the client application using the affected ActiveX control.

The following versions include the vulnerable software:

AOL 7.0 revision 4114.563
AOL 8.0 4129.230
AOL 9.0 Security Edition revision 4156.910

Other versions may also be affected.







 

Privacy Statement
Copyright 2008, SecurityFocus