Multiple Vulnerabilities in Yahoo! Messenger
Multiple vulnerabilities exist in Yahoo! Messenger that can lead to remote compromise of the affected system.
June 6, 2002
ReportedJune 5, 2002, by CERT.
VERSIONSAFFECTED
· Yahoo! Messenger 5, 0, 0, 1064 and earlier for Microsoft Windows
DESCRIPTION
Multiplevulnerabilities exist in Yahoo! Messenger that can lead to remote compromise ofthe affected system. The first vulnerability is a buffer overflow condition thatexists in the messenger Uniform Resource Identifier (URI) handler “ymsgr:”.The second vulnerability exists in theYahoo! Messenger "addview" function that lets an attacker executearbitrary script and HTML in the Internet security zone of the local machine.
VENDORRESPONSE
Thevendor, Yahoo!, recommends that affectedusers upgradeto version 5, 0, 0, 1065 or a laterversion.
CREDIT
Discoveredby ScottWoodward, Phuong Nguyen, and AdamLang.
About the Author
You May Also Like