GraceNote CDDBControl ActiveX Control Remote Buffer Overflow Vulnerability
21 Apr. 2012
Summary
Buffer overflow in GraceNote CDDBControl ActiveX Control, as used by multiple products that use Gracenote CDDB, allows remote attackers to execute arbitrary code via a long option string.
Vulnerable Systems:
* Sony SonicStage Mastering Studio 2.2.1
* Sony SonicStage Mastering Studio 2.2
* Sony SonicStage Mastering Studio 2.1.1
* Sony SonicStage Mastering Studio 2.1
* Sony SonicStage 3.4
* Sony SonicStage 3.3
* Sony CONNECT Player 0
* Nokia PC Suite 6.8
* Nokia PC Suite 6.7
* Justsystem BeatJam 2006
* GraceNote CDDBControl ActiveX 0
* AOL Client Software 9.0 Security
* AOL Client Software 8.0
* AOL Client Software 7.0
GraceNote CDDBControl ActiveX control is prone to a buffer-overflow vulnerability because the software fails to sufficiently bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Invoking the object from a malicious website or HTML email may trigger the condition. A successful exploit would corrupt process memory and allow arbitrary code to run in the context of the client application using the affected ActiveX control.
The following versions include the vulnerable software: