1. Symantec/
  2. Security Response/
  3. Attack Signatures/
  4. Web Attack: Yahoo! Messenger Webcam ActiveX

Web Attack: Yahoo! Messenger Webcam ActiveX

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

Description

This signature detects attempts to exploit a buffer overflow with a Yahoo ActiveX control which could result in remote code execution.

Additional Information

Yahoo! Messenger Webcam Upload ActiveX control is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.

This issue occurs when an excessive amount of data is passed to the application. The ActiveX control uses CLSID: DCE2F8B1-A520-11D4-8FD0-00D0B7730277.

Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of applications that use the affected control (typically Internet Explorer).

Affected

  • Yahoo! Messenger 8.0 2005.1.1.4, 8.0, 8.0.1, 8.1
  • Yahoo! Webcam ActiveX Control 2.0.1.4

Response

Ensure that all vendor supplied patches and security updates have been applied.
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube