[Full-disclosure] Yahoo! Messenger Service 18 Remote Buffer Overflow Vulnerability

Jain, Siddhartha Siddhartha.Jain at kla-tencor.com
Fri Oct 27 07:35:35 BST 2006


Did Yahoo put out a security notification yet? I don't see any mention
of a bug fix on the yahoo messenger page. And when I turn on my yahoo
messenger (ver 8.0.0.701), shouldn't I be alerted to receive an update?

- Siddhartha



-----Original Message-----
From: full-disclosure-bounces at lists.grok.org.uk
[mailto:full-disclosure-bounces at lists.grok.org.uk] On Behalf Of Gadi
Evron
Sent: Thursday, October 26, 2006 7:46 AM
To: cdejrhymeswithgay at hush.com
Cc: full-disclosure at lists.grok.org.uk; bugtraq at securityfocus.com
Subject: Re: [Full-disclosure] Yahoo! Messenger Service 18 Remote Buffer
Overflow Vulnerability

On Thu, 26 Oct 2006 cdejrhymeswithgay at hush.com wrote:
> So how fast is this "record time?" As fast as Hitler's Blitzkrieg
> tactics? That's pretty fast!

Yahoo! released a fixed version.

	Gadi.




Full-Disclosure is hosted and sponsored by Secunia.