Tuesday, June 12, 2007

Yahoo! I got two vulnerabilities!

Two vulnerabilities for the Yahoo! Messenger have been disclosed to the public. These vulnerabilities have been proven to result in arbitrary code execution, which means that it may just be a little time before it is exploited by malicious users. The first vulnerability is because of lack of boundary checking in the ywcupl.dll (used for Yahoo! Webcam Upload ActiveX control). This error can cause a stack based buffer overflow by assigning a very long string to the “Server” property and then calling the “Send()” method. The second vulnerability is because of lack of boundary checking in the ywcvwr.dll (used for Yahoo! Webcam Viewer ActiveX control). Not to worry though, because Yahoo! has already given an update which solves this issue. Please go to this site to know more about the vulnerability and how to update your Yahoo! Messengers.
Hmmm, time to check my own Yahoo Messenger...well I don't use it often ... but that's of course one of the problems, isn't it?