In association with heise online

24 August 2007, 11:15

Update for Yahoo Messenger

  • Twitter
  • Facebook
  • submit to slashdot
  • StumbleUpon
  • submit to reddit

The vendor has released an update for the vulnerability discovered about a week ago in Yahoo Messenger. This vulnerability can be exploited using invitations to webcam sessions to inject arbitrary code. In the interim, further details about the security vulnerability have been announced.

A vulnerability allows malicious code to be injected using specially crafted JPEG 2000 data streams, which Yahoo's Messenger uses for webcam sessions. A heap overflow can occur during the processing of manipulated data streams. A second vulnerability, which can be exploited if a user accepts a webcam invitation, only causes the software to crash.

The vulnerabilities reside in the files kdv_v32M.dll previous to Version 3.2.0.2 and ywcvwr.dll previous to Version 2.0.1.9, which are included in Yahoo Messenger 8.1.0.413 and previous versions. The vendor has provided a download of a vulnerability-free version. Users of the software should install the update as soon as possible.

See also:

(mba)

Print Version | Send by email | Permalink: http://h-online.com/-733508
 


  • July's Community Calendar





The H Open

The H Security

The H Developer

The H Internet Toolkit