Multiple Vulnerabilities in Yahoo! Messenger

Multiple vulnerabilities exist in Yahoo! Messenger that can lead to remote compromise of the affected system.

Ken Pfeil

June 6, 2002

1 Min Read
ITPro Today logo

ReportedJune 5, 2002, by CERT.

VERSIONSAFFECTED

·        Yahoo! Messenger 5, 0, 0, 1064 and earlier for Microsoft Windows

 

DESCRIPTION

Multiplevulnerabilities exist in Yahoo! Messenger that can lead to remote compromise ofthe affected system. The first vulnerability is a buffer overflow condition thatexists in the messenger Uniform Resource Identifier (URI) handler “ymsgr:”.The second vulnerability exists in theYahoo! Messenger "addview" function that lets an attacker executearbitrary script and HTML in the Internet security zone of the local machine.

VENDORRESPONSE

Thevendor, Yahoo!, recommends that affectedusers upgradeto version 5, 0, 0, 1065 or a laterversion.

 

CREDIT
Discoveredby ScottWoodward, Phuong Nguyen, and AdamLang.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like