Yahoo! Messenger Web Camera Invitation Handling Vulnerability
added August 16, 2007 at 10:05 am
US-CERT is aware of a publicly reported vulnerability in Yahoo! Messenger. By enticing a user to accept a specially crafted web camera invitation, a remote attacker may be able to execute arbitrary code on an affected system.
Until a fix is available, US-CERT recommends that users reject unsolicited web camera invitations and block outgoing network traffic on TCP port 5100.
US-CERT will continue to investigate and will provide additional information as it becomes available.
undefined
undefined