In association with heise online

24 August 2007, 12:15

Update for Yahoo Messenger

The vendor has released an update for the vulnerability discovered about a week ago in Yahoo Messenger. This vulnerability can be exploited using invitations to webcam sessions to inject arbitrary code. In the interim, further details about the security vulnerability have been announced.

A vulnerability allows malicious code to be injected using specially crafted JPEG 2000 data streams, which Yahoo's Messenger uses for webcam sessions. A heap overflow can occur during the processing of manipulated data streams. A second vulnerability, which can be exploited if a user accepts a webcam invitation, only causes the software to crash.

The vulnerabilities reside in the files kdv_v32M.dll previous to Version 3.2.0.2 and ywcvwr.dll previous to Version 2.0.1.9, which are included in Yahoo Messenger 8.1.0.413 and previous versions. The vendor has provided a download of a vulnerability-free version. Users of the software should install the update as soon as possible.

See also:

(mba)

  • Share this article
  • Twitter
  • Facebook
  • digg this
  • submit to slashdot
  • post to delicious
  • StumbleUpon
  • submit to reddit







The H open source

The H Security

The H Internet Toolkit