|
|
|
![]() |
Vulnerability Note VU#419419Yahoo! Messenger contains buffer overflow in "message" fieldOverviewYahoo! Messenger is an instant messaging client. There is a remotely exploitable buffer overflow vulnerability in the "message" field of Yahoo! Messenger.I. DescriptionA remotely exploitable buffer overflow exists in the "message" field that may permit a remote attacker to execute arbitrary code on the system with the privileges of the current user. It is possible to crash the Yahoo! Messenger client by overflowing the "message" field.It should be noted that the attacker needs to use a custom client in order to exploit this vulnerability.
The Yahoo! Messenger client communicates via port 5101 for peer to peer connections. Disabling the client, or blocking access to this port via a firewall may mitigate this attack.
References
This vulnerablity was discovered by Scott Woodward. This document was written by Jason Rafail.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||