First published: Wed Oct 25 2006(Updated: )
Buffer overflow in the AOL.PicDownloadCtrl.1 ActiveX control (YGPPicDownload.dll) 9.2.3.0 in America Online (AOL) 9.0 Security Edition allows remote attackers to execute arbitrary code via the downloadFileDirectory property, a different vulnerability than CVE-2006-5502.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AOL Server | =9.0 | |
=9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5501 has a high severity due to its potential for remote code execution.
To fix CVE-2006-5501, users should upgrade to a patched version of the AOL software that addresses this vulnerability.
CVE-2006-5501 affects the AOL 9.0 Security Edition, specifically the AOL.PicDownloadCtrl.1 ActiveX control.
Attackers can exploit CVE-2006-5501 by using the downloadFileDirectory property to trigger a buffer overflow.
CVE-2006-5501 can still pose a threat if users are running outdated versions of AOL 9.0 Security Edition.