Yahoo! Messenger 'YahooBridgeLib.dll' ActiveX Control Remote Denial of Service Vulnerability
BID:37007
Info
Yahoo! Messenger 'YahooBridgeLib.dll' ActiveX Control Remote Denial of Service Vulnerability
| Bugtraq ID: | 37007 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 12 2009 12:00AM |
| Updated: | Nov 12 2009 04:36PM |
| Credit: | HACKATTACK IT SECURITY GmbH |
| Vulnerable: |
Yahoo! Messenger 9.0.0.2162 Yahoo! Messenger 9 |
| Not Vulnerable: | |
Discussion
Yahoo! Messenger 'YahooBridgeLib.dll' ActiveX Control Remote Denial of Service Vulnerability
Yahoo! Messenger is prone to a denial-of-service vulnerability because of a NULL-pointer dereference error.
A successful attack allows a remote attacker to crash the application using the ActiveX control (typically Internet Explorer), denying further service to legitimate users. Given the nature of this issue, the attacker may also be able to run arbitrary code, but this has not been confirmed.
Yahoo! Messenger 9.0.0.2162 is vulnerable; other versions may also be affected.
Yahoo! Messenger is prone to a denial-of-service vulnerability because of a NULL-pointer dereference error.
A successful attack allows a remote attacker to crash the application using the ActiveX control (typically Internet Explorer), denying further service to legitimate users. Given the nature of this issue, the attacker may also be able to run arbitrary code, but this has not been confirmed.
Yahoo! Messenger 9.0.0.2162 is vulnerable; other versions may also be affected.
Exploit / POC
Yahoo! Messenger 'YahooBridgeLib.dll' ActiveX Control Remote Denial of Service Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user into visiting a malicious site.
The following exploit is available:
To exploit this issue, an attacker must entice an unsuspecting user into visiting a malicious site.
The following exploit is available:
Solution / Fix
Yahoo! Messenger 'YahooBridgeLib.dll' ActiveX Control Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Yahoo! Messenger 'YahooBridgeLib.dll' ActiveX Control Remote Denial of Service Vulnerability
References:
References: