A remote overflow exists in Gracenote CDDBControl ActiveX Control. The Gracenote CDDB fails to handle long option string resulting in a buffer overflow. With a specially crafted request, an attacker can execute arbitrary code resulting in a loss of integrity.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Private,
Exploit Unknown
OSVDB:
Web Related
Technical
Successful exploitation requires that the user is tricked into visiting a malicious website.
Solution
Upgrade to version 6.8 update or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.