Posted by Trancer on May 24 2009

AOLWrote a new Metaspoit exploit module for the AOL Radio AmpX ActiveX control ConvertFile() stack-based buffer overflow vulnerability.

This module exploits a stack-based buffer overflow in AOL IWinAmpActiveX class (AmpX.dll) version 2.4.0.6 installed via AOL Radio website. By setting an overly long value to ‘ConvertFile()’, an attacker can overrun a buffer and execute arbitrary code.

This vulnerability was found by rgod and was published recently by Nine:Situations:Group. Still no patch from AOL, if you want to test it you can get the vulnerable package here on the AOL Radio web site.

Download aol_ampx_convertfile.rb.
Also on Metasploit.

References:
BID 35028
OSVDB 54706
milw0rm 8733

Categories: Exploits, Metasploit

Leave a Reply


Follow Recognize-Security on Twitter