Secunia
|
|

CVE Reference: CVE-2006-5559 |
|
| NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE. | |
|
Original Page at CVE MITRE: CVE-2006-5559 |
|
|
Description: The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments. |
|
|
CVE Status: Candidate |
|
|
References: XF http://xforce.iss.net/xforce/xfdb/29837 ST 1017127 SAID Secunia Advisory: SA22452 OVAL http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:214 OSVDB 31882 MS http://www.microsoft.com/technet/security/Bulletin/MS07-009.mspx MISC http://research.eeye.com/html/alerts/zeroday/20061027.html http://blogs.technet.com/msrc/archive/2006/10/27/adodb-connection-poc-published.aspx MILW0RM http://milw0rm.com/exploits/2629 CERT-VN 589272 CERT http://www.us-cert.gov/cas/techalerts/TA07-044A.html BID 20704 |
|
| Return to the previous page. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |