Yahoo! Messenger Call Center Buffer Overflow Vulnerability

BID:4837

Info

Yahoo! Messenger Call Center Buffer Overflow Vulnerability

Bugtraq ID: 4837
Class: Boundary Condition Error
CVE: CVE-2002-0031
Remote: Yes
Local: No
Published: May 27 2002 12:00AM
Updated: Jul 11 2009 01:56PM
Credit: Discovered by Phuong Nguyen <[email protected]>.
Vulnerable: Yahoo! Messenger 5.0
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows ME
- Microsoft Windows NT Workstation 4.0 SP6a
- Microsoft Windows NT Workstation 4.0 SP5
- Microsoft Windows NT Workstation 4.0 SP4
- Microsoft Windows NT Workstation 4.0 SP3
- Microsoft Windows NT Workstation 4.0 SP2
- Microsoft Windows NT Workstation 4.0 SP1
- Microsoft Windows NT Workstation 4.0
- Microsoft Windows XP Home
Not Vulnerable: Yahoo! Messenger 5.0 .1065

Discussion

Yahoo! Messenger Call Center Buffer Overflow Vulnerability

Yahoo! Messenger configures the 'ymsgr:' URI handler when it is installed. The handler invokes YPAGER.EXE with the supplied parameters. YPAGER.EXE accepts the 'call' argument; it is used for starting the 'Call Center' feature.

There is a stack overrun condition in the 'Call Center' component that may be exploited through a specially constructed URI. It has been reported that the stack frame of the affected function will be corrupted if the argument to the 'call' parameter passed to YPAGER.EXE is of 268 bytes or greater in length.

Attackers may exploit this vulnerability to execute arbitrary code.

Solution / Fix

Yahoo! Messenger Call Center Buffer Overflow Vulnerability

Solution:
Yahoo has reportedly eliminated this vulnerability in Build 1065. It has been reported that a bug in the distribution mechanism may have caused Build 1036 to be installed on systems rather than Build 1065. This would leave unsuspecting users vulnerable. Users are advised to ensure that they are using 5,0,0,1065 and install it if they are not:


Yahoo! Messenger 5.0

References

Yahoo! Messenger Call Center Buffer Overflow Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report