AOL YGPPDownload AddPictureNoAlbum ActiveX Control Heap Corruption
25 Oct. 2006
Summary
America Online 9.0 Security Edition builds "upon Internet Explorer technology to offer its users enhanced security and usability features". America Online 9.0 Security Edition ships with an ActiveX control which is marked as safe for scripting and contains a buffer overflow vulnerability which allows for the arbitrary execution of code.
This control is registered as safe for scripting in IE and contains a buffer overflow in its AddPictureNoAlbum() method.
Solutions:
1. Users of AOL 9.0 or AOL 9.0 Security Edition are recommended to log in to the AOL service and a fix will be seamlessly applied to their system.
2. Users using versions of AOL that are older than 9.0 are strongly recommended to upgrade to the latest version of AOL 9.0 Security Edition."