Release date:
Updated on:
Affected Systems:
Yahoo! Messenger 11.x
Unaffected system:
Yahoo! Messenger 11.5.0.155
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51405
Cve id: CVE-2012-0268
Yahoo! Messenger is a popular instant messaging software.
Yahoo! Messenger has security vulnerabilities and can be exploited by malicious users to control the user system.
This vulnerability is caused by the "CYImage: LoadJPG ()" method (YImage. dll). You can use a JPG file to cause a heap buffer overflow.
<* Source: Tielei Wang (wangtielei@icst.pku.edu.cn)
Link: http://secunia.com/advisories/47041/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Yahoo!
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://messenger.yahoo.com/