PT-2007-5572 · Kakadu+1 · Kakadu+1

Publicado

2007-08-17

·

Atualizado

2017-07-29

·

CVE-2007-4391

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Yahoo! Messenger version 8.1.0.413
Description The issue is related to a heap-based buffer overflow in the Kakadu kdu v32m.dll component. This can be triggered by sending a specially crafted "invite to view my webcam" request with a certain length field in JPEG2000 data, potentially causing a denial of service (application crash). When the request is accepted, it may allow an attacker to inject a DLL into the peer Yahoo! Messenger application.
Recommendations For Yahoo! Messenger version 8.1.0.413, consider disabling the handling of JPEG2000 data in the Kakadu kdu v32m.dll component as a temporary workaround until a patch is available. Restrict access to the "invite to view my webcam" feature to minimize the risk of exploitation.

Exploit

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-4391

Produtos afetados

Kakadu
Yahoo! Messenger