OSVDB ID: 26874

Title: Gracenote CDDBControl ActiveX Control Option String Overflow

Info

Disclosure

Jun 27, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

A remote overflow exists in Gracenote CDDBControl ActiveX Control. The Gracenote CDDB fails to handle long option string resulting in a buffer overflow. With a specially crafted request, an attacker can execute arbitrary code resulting in a loss of integrity.

Classification

Location: Remote / Network Access, Context Dependent
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Private, Exploit Unknown
OSVDB: Web Related

Solution

Upgrade to version 6.8 update or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Sony

Connect Player

Unknown or Unspecified

SonicStage

3.3
3.4

SonicStage Mastering Studio

2.1
2.2

Nokia

PC Suite

6.7
6.8

References

Credit

  • Peter Vreugdenhil -
  • Dan Plakosh -
  • Richard Smith -


Direct URL: http://osvdb.org/26874