>> Nokia PC Suite Gracenote CDDB ActiveX Control Remote Buffer Overflow Vulnerability
Title : Nokia PC Suite Gracenote CDDB ActiveX Control Remote Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2006-2563 CVE ID : CVE-2006-3134
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-06-27
Technical Description
A vulnerability has been identified in Nokia PC Suite, which could be exploited by remote attackers to take complete control of an affected system. This flaw is due to a buffer overflow error in the Gracenote CDDB (CD Data Base) ActiveX Control when handling an overly long option, which could be exploited by remote attackers to execute arbitrary commands on a vulnerable system via a specially crafted Web page.