[Full-disclosure] AOL ActiveX - Hail to The Francis



Product:

AOL 9.5

Vulnerability:

ActiveX - Heap Overflow

Discussion:

Vulnerability is in Activex Control ("CDDBControl.dll")
Sending a string to BindToFile() , triggering the vulnerability.
Successful exploits allow remote attackers to execute arbitrary
code.

Debugger Results:

(fd0.1274): Access violation - code c0000005 (!!! second chance !!!)
eax=7efefefe ebx=00000000 ecx=0020d7c0 edx=41414141 esi=03465df0
edi=02b82000
eip=10033011 esp=0020cdac ebp=0020ed20 iopl=0 nv up ei pl zr na pe
nc

Credits:

Celil 'karak0rsan' Unuver and murderkey
from Hellcode Research

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • AOL 9.5 ActiveX Heap Overflow Vulnerability
    ... Vulnerability is in Activex Control ... triggering the vulnerability. ... Successful exploits allow remote attackers to execute arbitrary code. ...
    (Bugtraq)
  • Re: [Full-disclosure] Nmap NOT VULNERABLE to Windows DLL Hijacking
    ... current working directory in that search path. ...  Cross-site scripting vulnerability in Mozilla Firefox before ... which allows remote attackers to bypass ...  to execute arbitrary code via vectors involving access to a deleted ...
    (Full-Disclosure)
  • SecurityFocus Microsoft Newsletter #343
    ... Microsoft VDT Database Designer VDT70.DLL ActiveX Control Denial Of Service Vulnerability ... Attackers can exploit this issue to crash Internet Explorer or other applications that use the vulnerable ActiveX control, resulting in denial-of-service conditions. ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #344
    ... MICROSOFT VULNERABILITY SUMMARY ... Avira Antivir Tar Archive Handling Remote Denial Of Service Vulnerability ... EDraw Office Viewer Component EDrawOfficeViewer.OCX ActiveX Control Buffer Overflow Vulnerability ...
    (Focus-Microsoft)
  • [Full-disclosure] [SECURITY] [DSA 2245-1] chromium-browser security update
    ... Use-after-free vulnerability in the frame-loader implementation in Google ... have unspecified other impact via unknown vectors. ... Chrome allows remote attackers to cause a denial of service or possibly have ... Use-after-free vulnerability in Google Chrome allows remote attackers to cause ...
    (Full-Disclosure)