Yahoo! Messenger Service 18 Remote Buffer Overflow Vulnerability
BID:20625
Info
Yahoo! Messenger Service 18 Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 20625 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 19 2006 12:00AM |
| Updated: | Oct 26 2006 07:23PM |
| Credit: | Gianni Amato is credited with discovering this issue. |
| Vulnerable: |
Yahoo! Messenger 8.0 |
| Not Vulnerable: | |
Discussion
Yahoo! Messenger Service 18 Remote Buffer Overflow Vulnerability
Yahoo! Messenger is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
This vulnerability allows remote attackers to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will likely crash the server, denying further service to legitimate users.
Yahoo! Messenger 8 with Voice is vulnerable.
Yahoo! Messenger is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
This vulnerability allows remote attackers to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will likely crash the server, denying further service to legitimate users.
Yahoo! Messenger 8 with Voice is vulnerable.
Exploit / POC
Yahoo! Messenger Service 18 Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Yahoo! Messenger Service 18 Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].