PT-2008-2248 · Yahoo · Yahoo! Music Jukebox

Krystian Kloskowski

·

Published

2008-02-06

·

Updated

2017-09-29

·

CVE-2008-0623

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Yahoo! Music Jukebox version 2.2.2.056
Description The issue is a stack-based buffer overflow in the YMP Datagrid ActiveX control, specifically in the datagrid.dll component. This occurs when a long argument is passed to the AddImage method, allowing remote attackers to execute arbitrary code.
Recommendations For Yahoo! Music Jukebox version 2.2.2.056, consider disabling the AddImage method in the YMP Datagrid ActiveX control as a temporary workaround until a patch is available.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-0623

Affected Products

Yahoo! Music Jukebox