|
GraceNote CDDBControl ActiveX Control Remote Buffer Overflow Vulnerability
GraceNote CDDBControl ActiveX control is prone to a buffer-overflow vulnerability because the software fails to sufficiently bounds-check user-supplied input before copying it to an insufficiently sized memory buffer. Invoking the object from a malicious website or HTML email may trigger the condition. A successful exploit would corrupt process memory and allow arbitrary code to run in the context of the client application using the affected ActiveX control. The following versions include the vulnerable software: AOL 7.0 revision 4114.563 AOL 8.0 4129.230 AOL 9.0 Security Edition revision 4156.910 Other versions may also be affected. |
|
|
Privacy Statement |