|
|
| |
Credit:
The information has been provided by Peter Vreugdenhi
The original article can be found at: http://www.securityfocus.com/bid/18678/info
|
| |
Vulnerable Systems:
* Sony SonicStage Mastering Studio 2.2.1
* Sony SonicStage Mastering Studio 2.2
* Sony SonicStage Mastering Studio 2.1.1
* Sony SonicStage Mastering Studio 2.1
* Sony SonicStage 3.4
* Sony SonicStage 3.3
* Sony CONNECT Player 0
* Nokia PC Suite 6.8
* Nokia PC Suite 6.7
* Justsystem BeatJam 2006
* GraceNote CDDBControl ActiveX 0
* AOL Client Software 9.0 Security
* AOL Client Software 8.0
* AOL Client Software 7.0
GraceNote CDDBControl ActiveX control is prone to a buffer-overflow vulnerability because the software fails to sufficiently bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Invoking the object from a malicious website or HTML email may trigger the condition. A successful exploit would corrupt process memory and allow arbitrary code to run in the context of the client application using the affected ActiveX control.
The following versions include the vulnerable software:
* AOL 7.0 revision 4114.563
* AOL 8.0 4129.230
* AOL 9.0 Security Edition revision 4156.910
Other versions may also be affected.
Vendor Status:
Nokia had issued an update for this vulnerability .
CVE Information:
CVE-2006-3134
|
|
|