AOL Patches Critical Browser Bug

An ActiveX control shipped with AOL's Web access software can be used by attackers to hijack users' PCs, security companies said Thursday. AOL has released a fix, and urged users to log on to obtain it.

According to Reston, Va.-based iDefense Labs, America Online 9.0 Security Edition -- which is based on Microsoft's Internet Explorer 6.0 browser -- uses an ActiveX control dubbed "YGPPDownload" that can be exploited using two separate flaws in the control's code. AOL Patches Critical Browser Bug - News by InformationWeek

Linked by shanmuga Sunday, 29th October 2006 9:29PM