Browsers - Code Execution Flaw Haunts AOL Radio - eWeek Security Watch

Code Execution Flaw Haunts AOL Radio

Written By
Ryan Naraine
Ryan Naraine
Jan 10, 2008
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

The U.S. Computer Emergency Readiness Team has issued a high-risk warning for a serious security flaw affecting users of America Online’s AOL Radio software.

The vulnerability is described as a stack buffer overflow that could allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.

The US-CERT warning, written by vulnerability analyst Will Dormann, states the bug exists in the AmpX ActiveX control used by AOL Radio to handle streaming audio in Web pages.

““The AOL AmpX ActiveX control, which is provided by AmpX.dll, uses a program called AOLMediaPlaybackControl.exe. The AOLMediaPlaybackControl application contains a stack buffer overflow that is exploitable via the AmpX ActiveX control’s AppendFileToPlayList() method.”“

A malicious hacker could trick a user to load a booby-trapped HTML document (Web page or e-mail message/attachment) to load malware or take complete control over a Windows computer running AOL Radio, Dormann said.

America Online has not publicly acknowledged the issue, but Dormann said the flaw was addressed in an “unspecified automatic update” that removed the AmpX control and AOLMediaPlaybackControl.exe.

Users unable to apply an update should disable the AmpX ActiveX control in Internet Explorer, Dormann said.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.