PT-2007-5572 · Kakadu+1 · Kakadu+1
Publicado
2007-08-17
·
Atualizado
2017-07-29
·
CVE-2007-4391
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Yahoo! Messenger version 8.1.0.413
Description
The issue is related to a heap-based buffer overflow in the Kakadu kdu v32m.dll component. This can be triggered by sending a specially crafted "invite to view my webcam" request with a certain length field in JPEG2000 data, potentially causing a denial of service (application crash). When the request is accepted, it may allow an attacker to inject a DLL into the peer Yahoo! Messenger application.
Recommendations
For Yahoo! Messenger version 8.1.0.413, consider disabling the handling of JPEG2000 data in the Kakadu kdu v32m.dll component as a temporary workaround until a patch is available. Restrict access to the "invite to view my webcam" feature to minimize the risk of exploitation.
Exploit
Correção
RCE
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Kakadu
Yahoo! Messenger