full-disclosure-uk January 2010 archive
Main Archive Page > Month Archives  > full-disclosure-uk archives
full-disclosure-uk: [Full-disclosure] AOL ActiveX - Hail to The

[Full-disclosure] AOL ActiveX - Hail to The Francis

From: <phc_at_nospam>
Date: Mon Jan 18 2010 - 18:16:10 GMT
To: full-disclosure@lists.grok.org.uk


Product:

AOL 9.5 Vulnerability:

ActiveX - Heap Overflow

Discussion:

Vulnerability is in Activex Control ("CDDBControl.dll") Sending a string to BindToFile() , triggering the vulnerability. Successful exploits allow remote attackers to execute arbitrary code.

Debugger Results:

(fd0.1274): Access violation - code c0000005 (!!! second chance !!!) eax=7efefefe ebx=00000000 ecx=0020d7c0 edx=41414141 esi=03465df0 edi=02b82000 eip=10033011 esp=0020cdac ebp=0020ed20 iopl=0 nv up ei pl zr na pe nc

Credits:

Celil 'karak0rsan' Unuver and murderkey
from Hellcode Research



Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/