Full Disclosure mailing list archives
Advisory 2006-03-11 Heap Overflow in AOL Client Software
From: gat0r <gat0r () toughguy net>
Date: Sat, 11 Mar 2006 23:00:12 -0800
Advisory 2006-03-11 Heap Overflow in AOL Client Software I. BACKGROUND Advisory marked for immediate release. II. DESCRIPTION It is possible to make AOL Client Software crash or run arbitrary code by the use of malformed input. III. HISTORY This advisory has no history. IV. WORKAROUND There are no known workarounds. V. VENDOR RESPONSE AOL Client Software has not commented on this issue. VI. CVE INFORMATION The Common Vulnerabilities and Exposures (CVE) project has assigned the name CVE-2006-251293 to this issue. APPENDIX A. - Vendor Information http://www.aol.com APPENDIX B. - References NONE CONTACT: *gat0r bantown () spam la *1-888-LOL-WHAT *CISSP GSAE CCE CEH CSFA GREM SSP-CNSA SSP-MPA GIPS GHTQ GWAS _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Advisory 2006-03-11 Heap Overflow in AOL Client Software gat0r (Mar 11)