First published: Fri Oct 09 2009(Updated: )
Use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control (sb.dll) in America Online (AOL) 9.5.0.1 allows remote attackers to trigger memory corruption or possibly execute arbitrary code via a malformed argument to the SetSuperBuddy method.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Aol Superbuddy ActiveX Control | =9.5.0.1 | |
Aol Superbuddy Activex Control | =9.5.0.1 | |
AOL Internet Software | =9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3658 is rated as high severity due to its potential for remote code execution.
To fix CVE-2009-3658, it is recommended to update to the latest version of the affected AOL software.
CVE-2009-3658 affects AOL version 9.5.0.1 and AOL Internet Software version 9.1.
CVE-2009-3658 is a use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control.
Yes, CVE-2009-3658 can be exploited remotely through a malformed argument to the SetSuperBuddy method.