Chinese Internet Security Response Team (GMT +0800)

Multiple Yahoo! Messenger PoCs in the wild

[Post on : June 9, 2007 18:19 | Category : Exploit & Vulnerability | by : smallmo] Reship : Original

Vulnerabilities of Yahoo! Messenger Webcam 8.1 have been reported by most of securtiy vendors these two days. As while, four proof-of-concept exploits have been published since June.7. Two of them are about Yahoo! Messenger Webcam 8.1 ActiveX Remote Buffer Overflow, another two are about Yahoo! Messenger Webcam 8.1 (Ywcvwr.dll/Ywcupl.dll) Download / Execute.

These exploits can be used to create the .html files which contains the related vulnerabilities. We think these cracked .html files will be appeared in the compromised sites in the future. Fortunately, Yahoo has already released a new version to fix these vulnerabilities.

Yahoo Security suggestion: Yahoo! Webcam ActiveX Controls

New version: http://messenger.yahoo.com/



Last modified by smallmo onJune 9, 2007 18:39

akira Says : Email
April 14, 2008 14:49
cool
Pages: 1/1 First page 1 Final page