AOL "YGP Picture Finder Tool" ActiveX Control Buffer Overflow Vulnerability

A vulnerability has been identified in AOL software and AOL You’ve Got Pictures, which could be exploited by remote attackers to execute arbitrary commands. This flaw is due to a buffer overflow error in the AOL YGP Picture Finder Tool ActiveX control (YGPPicFinder.dll) that does not properly handle overly long input strings, which could be exploited by remote attackers to compromise a vulnerable system by convincing a user to visit a specially crafted web page.


Affected Products


AOL version 8.0
AOL version 8.0+
AOL version 9.0 Classic


Solution


Upgrade to AOL 9.0 Optimized or AOL 9.0 Security Edition http://downloads.channel.aol.com/ or download and apply the hotfix


http://www.frsirt.com/english/advisories/2006/022

Leave a Reply