Yahoo! Music Jukebox ActiveX Multiple Buffer Overflow Vulnerabilities
RISK: Medium Risk
Multiple vulnerabilities have been identified in Yahoo! Music Jukebox, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. These issues are caused by buffer overflow errors in the "datagrid.dll" and "mediagrid.dll" ActiveX controls when processing overly long arguments passed to certain methods (e.g. "AddImage()", "AddButton()" or "AddBitmap()"), which could be exploited by remote attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.
Impact
- Denial of Service
- Remote Code Execution
System / Technologies affected
- Yahoo! Music Jukebox version 2.2.2.056 and prior
Solutions
Set kill bits for the CLSIDs
{5F810AFC-BB5F-4416-BE63-E01DD117BD6C}
and
{22FD7C0A-850C-4A53-9821-0B0915C96139}.
How to set the kill bits :
1.Use Registry Editor to view the data value of the Compatibility Flags DWORD value of the ActiveX object CLSID in the following registry key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\CLSID of the ActiveX control
where CLSID of the ActiveX Control is the class identifier of the appropriate ActiveX control.
2. Change the value of the Compatibility Flags DWORD value to 0x00000400.
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with