Yahoo! Messenger YMailAttach ActiveX Control Remote Buffer Overflow Vulnerability
BID:21607
Info
Yahoo! Messenger YMailAttach ActiveX Control Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 21607 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-6603 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2006 12:00AM |
| Updated: | Jan 02 2007 11:11PM |
| Credit: | Peter Vreugdenhil reported this vulnerability to iDefense Labs. |
| Vulnerable: |
Yahoo! Messenger 8.0 Yahoo! Messenger 7.5 .814 Yahoo! Messenger 7.0 .438 Yahoo! Messenger 6.0 .0.1921 Yahoo! Messenger 6.0 .0.1750 Yahoo! Messenger 6.0 .0.1643 Yahoo! Messenger 6.0 Yahoo! Messenger 5.6 .0.1358 Yahoo! Messenger 5.6 .0.1356 Yahoo! Messenger 5.6 .0.1355 Yahoo! Messenger 5.6 .0.1351 Yahoo! Messenger 5.6 .0.1347 Yahoo! Messenger 5.6 Yahoo! Messenger 5.5 .1249 Yahoo! Messenger 5.5 Yahoo! Messenger 5.0 .1232 Yahoo! Messenger 5.0 .1065 Yahoo! Messenger 5.0 .1046 Yahoo! Messenger 5.0 Yahoo! Messenger 8.0.0.863 |
| Not Vulnerable: |
Yahoo! Messenger 8.0 2005.1.1.4 |
Discussion
Yahoo! Messenger YMailAttach ActiveX Control Remote Buffer Overflow Vulnerability
The YMailAttach ActiveX control shipped with Yahoo! Messenger is prone to a buffer-overflow vulnerability. The software fails to perform sufficient bounds-checking of user-supplied input before copying it to an insufficiently sized memory buffer.
Yahoo! Messenger versions released prior to November 2, 2006 are vulnerable to this issue.
The YMailAttach ActiveX control shipped with Yahoo! Messenger is prone to a buffer-overflow vulnerability. The software fails to perform sufficient bounds-checking of user-supplied input before copying it to an insufficiently sized memory buffer.
Yahoo! Messenger versions released prior to November 2, 2006 are vulnerable to this issue.
Exploit / POC
Yahoo! Messenger YMailAttach ActiveX Control Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution / Fix
Yahoo! Messenger YMailAttach ActiveX Control Remote Buffer Overflow Vulnerability
Solution:
The vendor has released software updates to address this issue. Yahoo! Messenger versions that were obtained after November 2, 2006 are not vulnerable to this issue.
Version 2005.1.1.4 is available to address this issue; please see the reference section for details.
Yahoo! Messenger 8.0.0.863
Yahoo! Messenger 5.0 .1065
Yahoo! Messenger 5.0 .1046
Yahoo! Messenger 5.0 .1232
Yahoo! Messenger 5.0
Yahoo! Messenger 5.5
Yahoo! Messenger 5.5 .1249
Yahoo! Messenger 5.6 .0.1358
Yahoo! Messenger 5.6 .0.1347
Yahoo! Messenger 5.6 .0.1351
Yahoo! Messenger 5.6 .0.1356
Yahoo! Messenger 5.6
Yahoo! Messenger 5.6 .0.1355
Yahoo! Messenger 6.0 .0.1750
Yahoo! Messenger 6.0 .0.1643
Yahoo! Messenger 6.0
Yahoo! Messenger 6.0 .0.1921
Yahoo! Messenger 7.0 .438
Yahoo! Messenger 7.5 .814
Yahoo! Messenger 8.0
Solution:
The vendor has released software updates to address this issue. Yahoo! Messenger versions that were obtained after November 2, 2006 are not vulnerable to this issue.
Version 2005.1.1.4 is available to address this issue; please see the reference section for details.
Yahoo! Messenger 8.0.0.863
-
Yahoo! msgr8us.exe
http://us.dl1.yimg.com/download.yahoo.com/dl/msgr8/us/msgr8us.exe
Yahoo! Messenger 5.0 .1065
-
Yahoo! msgr8us.exe
http://us.dl1.yimg.com/download.yahoo.com/dl/msgr8/us/msgr8us.exe
Yahoo! Messenger 5.0 .1046
-
Yahoo! msgr8us.exe
http://us.dl1.yimg.com/download.yahoo.com/dl/msgr8/us/msgr8us.exe
Yahoo! Messenger 5.0 .1232
-
Yahoo! msgr8us.exe
http://us.dl1.yimg.com/download.yahoo.com/dl/msgr8/us/msgr8us.exe
Yahoo! Messenger 5.0
-
Yahoo! msgr8us.exe
http://us.dl1.yimg.com/download.yahoo.com/dl/msgr8/us/msgr8us.exe
Yahoo! Messenger 5.5
-
Yahoo! msgr8us.exe
http://us.dl1.yimg.com/download.yahoo.com/dl/msgr8/us/msgr8us.exe
Yahoo! Messenger 5.5 .1249
-
Yahoo! msgr8us.exe
http://us.dl1.yimg.com/download.yahoo.com/dl/msgr8/us/msgr8us.exe
Yahoo! Messenger 5.6 .0.1358
-
Yahoo! msgr8us.exe
http://us.dl1.yimg.com/download.yahoo.com/dl/msgr8/us/msgr8us.exe
Yahoo! Messenger 5.6 .0.1347
-
Yahoo! msgr8us.exe
http://us.dl1.yimg.com/download.yahoo.com/dl/msgr8/us/msgr8us.exe
Yahoo! Messenger 5.6 .0.1351
-
Yahoo! msgr8us.exe
http://us.dl1.yimg.com/download.yahoo.com/dl/msgr8/us/msgr8us.exe
Yahoo! Messenger 5.6 .0.1356
-
Yahoo! msgr8us.exe
http://us.dl1.yimg.com/download.yahoo.com/dl/msgr8/us/msgr8us.exe
Yahoo! Messenger 5.6
-
Yahoo! msgr8us.exe
http://us.dl1.yimg.com/download.yahoo.com/dl/msgr8/us/msgr8us.exe
Yahoo! Messenger 5.6 .0.1355
-
Yahoo! msgr8us.exe
http://us.dl1.yimg.com/download.yahoo.com/dl/msgr8/us/msgr8us.exe
Yahoo! Messenger 6.0 .0.1750
-
Yahoo! msgr8us.exe
http://us.dl1.yimg.com/download.yahoo.com/dl/msgr8/us/msgr8us.exe
Yahoo! Messenger 6.0 .0.1643
-
Yahoo! msgr8us.exe
http://us.dl1.yimg.com/download.yahoo.com/dl/msgr8/us/msgr8us.exe
Yahoo! Messenger 6.0
-
Yahoo! msgr8us.exe
http://us.dl1.yimg.com/download.yahoo.com/dl/msgr8/us/msgr8us.exe
Yahoo! Messenger 6.0 .0.1921
-
Yahoo! msgr8us.exe
http://us.dl1.yimg.com/download.yahoo.com/dl/msgr8/us/msgr8us.exe
Yahoo! Messenger 7.0 .438
-
Yahoo! msgr8us.exe
http://us.dl1.yimg.com/download.yahoo.com/dl/msgr8/us/msgr8us.exe
Yahoo! Messenger 7.5 .814
-
Yahoo! msgr8us.exe
http://us.dl1.yimg.com/download.yahoo.com/dl/msgr8/us/msgr8us.exe
Yahoo! Messenger 8.0
-
Yahoo! msgr8us.exe
http://us.dl1.yimg.com/download.yahoo.com/dl/msgr8/us/msgr8us.exe
References
Yahoo! Messenger YMailAttach ActiveX Control Remote Buffer Overflow Vulnerability
References:
References:
- Vulnerability Note VU#901852 (US-CERT)
- Yahoo! ActiveX Update (Yahoo!)
- Yahoo! Messenger Homepage (Yahoo!)
- iDefense Advisory: Yahoo Messenger YMailAttach ActiveX Control Heap Corruption V (iDefense)