Yahoo! Messenger Address Book Remote Buffer Overflow Vulnerabilitiy
BID:24926
Info
Yahoo! Messenger Address Book Remote Buffer Overflow Vulnerabilitiy
| Bugtraq ID: | 24926 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-3928 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 16 2007 12:00AM |
| Updated: | May 07 2015 05:36PM |
| Credit: | Rajesh Sethumadhavan is credited with the discovery of this issue. |
| Vulnerable: |
Yahoo! Messenger 8.1 Yahoo! Messenger 8.0.1 Yahoo! Messenger 8.0 Yahoo! Messenger 7.5 .814 Yahoo! Messenger 7.0 .438 Yahoo! Messenger 6.0 .0.1921 Yahoo! Messenger 6.0 .0.1750 Yahoo! Messenger 6.0 .0.1643 Yahoo! Messenger 6.0 Yahoo! Messenger 5.6 .0.1358 Yahoo! Messenger 5.6 .0.1356 Yahoo! Messenger 5.6 .0.1355 Yahoo! Messenger 5.6 .0.1351 Yahoo! Messenger 5.6 .0.1347 Yahoo! Messenger 5.6 Yahoo! Messenger 5.5 .1249 Yahoo! Messenger 5.5 Yahoo! Messenger 5.0 .1232 Yahoo! Messenger 5.0 .1065 Yahoo! Messenger 5.0 .1046 Yahoo! Messenger 5.0 Yahoo! Messenger 4.0 Yahoo! Messenger 8.0.0.863 Yahoo! Messenger 8.0 2005.1.1.4 |
| Not Vulnerable: | |
Discussion
Yahoo! Messenger Address Book Remote Buffer Overflow Vulnerabilitiy
Yahoo! Messenger is prone to a remote buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code in the context of the application or to cause denial-of-service conditions.
Yahoo! Messenger 8.1 and prior versions are vulnerable.
Yahoo! Messenger is prone to a remote buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code in the context of the application or to cause denial-of-service conditions.
Yahoo! Messenger 8.1 and prior versions are vulnerable.
Exploit / POC
Yahoo! Messenger Address Book Remote Buffer Overflow Vulnerabilitiy
To exploit this issue, an attacker must entice an unsuspecting user to interact with a maliciously crafted address book when using the affected application.
The following proof-of-concept information is available:
1. Create an address book entry using Yahoo! portal with a large amount of 'a's in 'email address' textbox.
2. Log in to Yahoo! Messenger
3. Go to the address book tab
4. Place your mouse pointer over the specially crafted address book entry
5. Yahoo! Messenger will immediately crash
To exploit this issue, an attacker must entice an unsuspecting user to interact with a maliciously crafted address book when using the affected application.
The following proof-of-concept information is available:
1. Create an address book entry using Yahoo! portal with a large amount of 'a's in 'email address' textbox.
2. Log in to Yahoo! Messenger
3. Go to the address book tab
4. Place your mouse pointer over the specially crafted address book entry
5. Yahoo! Messenger will immediately crash
Solution / Fix
Yahoo! Messenger Address Book Remote Buffer Overflow Vulnerabilitiy
Solution:
Reports indicate that the vendor has addressed this issue with a server-side fix, but Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reports indicate that the vendor has addressed this issue with a server-side fix, but Symantec has not confirmed this. Please contact the vendor for more information.
References
Yahoo! Messenger Address Book Remote Buffer Overflow Vulnerabilitiy
References:
References:
- Yahoo Messenger 8.1 Buffer Overflow (Rajesh Sethumadhavan)
- Yahoo! Instant Messenger Homepage (Yahoo!)