CVE-2009-3658: Use After Free
Published Oct 9, 2009
·Updated
Use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control (sb.dll) in America Online (AOL) 9.5.0.1 allows remote attackers to trigger memory corruption or possibly execute arbitrary code via a malformed argument to the SetSuperBuddy method.
Affected Software
3 affected components
AOL Sb.superbuddy.1 Active X Control=9.5.0.1
AOL Internet Software=9.1
AOL Superbuddy Activex Control=9.5.0.1
Event History
Oct 9, 2009
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
Description
Data Sourced
02:30 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-3658?
CVE-2009-3658 is rated as high severity due to its potential for remote code execution.
2
How do I fix CVE-2009-3658?
To fix CVE-2009-3658, it is recommended to update to the latest version of the affected AOL software.
3
What software is affected by CVE-2009-3658?
CVE-2009-3658 affects AOL version 9.5.0.1 and AOL Internet Software version 9.1.
4
What type of vulnerability is CVE-2009-3658?
CVE-2009-3658 is a use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control.
5
Can CVE-2009-3658 be exploited remotely?
Yes, CVE-2009-3658 can be exploited remotely through a malformed argument to the SetSuperBuddy method.