vendor:
Yahoo! Messenger
by:
minhbq
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Yahoo! Messenger
Affected Version From: Up to 2007.8.27.1
Affected Version To:
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested: Windows XP Professional SP2 with all patches, Internet Explorer 7
2007
Yahoo! Messenger (YVerInfo.dll <= 2007.8.27.1) ActiveX Control Buffer Overflows
This exploit targets the YVerInfo.dll ActiveX control in Yahoo! Messenger versions up to 2007.8.27.1. It allows for buffer overflow attacks through the 'fvcom' or 'info' functions. The exploit is scriptable and can be exploited using the HeapSpray technique. The control can only be called if it believes it is being run from the yahoo.com domain. The exploit was tested on Windows XP Professional SP2 with all patches and Internet Explorer 7.
Mitigation:
Apply the security update provided by Yahoo! Messenger (link: http://messenger.yahoo.com/security_update.php?id=082907).