This application requires Javascript for optimal performance.

AOL.Desktop.Rtx.File.Remote.Buffer.Overflow

Release Date

Jul 11, 2011

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against a buffer overflow vulnerability in AOL Desktop.

The vulnerability is caused by a boundary error in the "rich.rct" DLL library when processing Rich Text files (".rtx"). It can be exploited to cause a heap based buffer overflow via an overly long string in the "HREF" attribute of the "A" HTML tag.

Affected Products

AOL Desktop 9.6

Recommended Actions

Currently we are not aware of any vendor supplied patch for this issue.

Coverage

IPS
VCM

Reference/s

http://secunia.com/advisories/43136/
http://www.securityfocus.com/bid/46129 (BugTraq)
http://www.exploit-db.com/exploits/16107/

Reference: VID-26888