Yahoo! Messenger Call Center Buffer Overflow Vulnerability
BID:4837
Info
Yahoo! Messenger Call Center Buffer Overflow Vulnerability
| Bugtraq ID: | 4837 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0031 |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 2002 12:00AM |
| Updated: | Jul 11 2009 01:56PM |
| Credit: | Discovered by Phuong Nguyen <[email protected]>. |
| Vulnerable: |
Yahoo! Messenger 5.0 |
| Not Vulnerable: |
Yahoo! Messenger 5.0 .1065 |
Discussion
Yahoo! Messenger Call Center Buffer Overflow Vulnerability
Yahoo! Messenger configures the 'ymsgr:' URI handler when it is installed. The handler invokes YPAGER.EXE with the supplied parameters. YPAGER.EXE accepts the 'call' argument; it is used for starting the 'Call Center' feature.
There is a stack overrun condition in the 'Call Center' component that may be exploited through a specially constructed URI. It has been reported that the stack frame of the affected function will be corrupted if the argument to the 'call' parameter passed to YPAGER.EXE is of 268 bytes or greater in length.
Attackers may exploit this vulnerability to execute arbitrary code.
Yahoo! Messenger configures the 'ymsgr:' URI handler when it is installed. The handler invokes YPAGER.EXE with the supplied parameters. YPAGER.EXE accepts the 'call' argument; it is used for starting the 'Call Center' feature.
There is a stack overrun condition in the 'Call Center' component that may be exploited through a specially constructed URI. It has been reported that the stack frame of the affected function will be corrupted if the argument to the 'call' parameter passed to YPAGER.EXE is of 268 bytes or greater in length.
Attackers may exploit this vulnerability to execute arbitrary code.
Solution / Fix
Yahoo! Messenger Call Center Buffer Overflow Vulnerability
Solution:
Yahoo has reportedly eliminated this vulnerability in Build 1065. It has been reported that a bug in the distribution mechanism may have caused Build 1036 to be installed on systems rather than Build 1065. This would leave unsuspecting users vulnerable. Users are advised to ensure that they are using 5,0,0,1065 and install it if they are not:
Yahoo! Messenger 5.0
Solution:
Yahoo has reportedly eliminated this vulnerability in Build 1065. It has been reported that a bug in the distribution mechanism may have caused Build 1036 to be installed on systems rather than Build 1065. This would leave unsuspecting users vulnerable. Users are advised to ensure that they are using 5,0,0,1065 and install it if they are not:
Yahoo! Messenger 5.0
-
Yahoo! Messenger 5.0 Build 1065
Build 1065.
http://download.yahoo.com/dl/installs/ymsgr/ymsgr_1065.exe