[Full-disclosure] Advisory 2006-03-11Local Privilege Escalation Vulnerability in AOL Client Software



Advisory 2006-03-11 Local Privilege Escalation Vulnerability in AOL Client Software

I. BACKGROUND

Advisory marked for immediate release.

II. DESCRIPTION

AOL Client Software incorrectly validates user input

III. HISTORY

This advisory has no history.

IV. WORKAROUND

There are no known workarounds.

V. VENDOR RESPONSE

AOL Client Software has not commented on this issue.

VI. CVE INFORMATION

The Common Vulnerabilities and Exposures (CVE) project has assigned the
name CVE-2006-636555 to this issue.

APPENDIX A. - Vendor Information
http://www.aol.com
APPENDIX B. - References
NONE

CONTACT:
*ZATAZ Audits bantown@xxxxxxx
*1-888-LOL-WHAT
*CISSP GSAE CCE CEH CSFA GREM SSP-CNSA SSP-MPA GIPS GHTQ GWAS


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages