CVE-2002-0031: Buffer Overflow
Published Jun 11, 2002
·Updated
Buffer overflows in Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary code via a ymsgr URI with long arguments to (1) call, (2) sendim, (3) getimv, (4) chat, (5) addview, or (6) addfriend.
Affected Software
1 affected component
Yahoo Messenger=5.0
Remediation
Patch Available
Patch Available
Event History
Jun 11, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0031?
CVE-2002-0031 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2002-0031?
To fix CVE-2002-0031, upgrade to a version of Yahoo Messenger later than 5.0.0.1064.
3
What software is affected by CVE-2002-0031?
CVE-2002-0031 affects Yahoo Messenger version 5.0 and earlier.
4
What types of attacks are possible with CVE-2002-0031?
CVE-2002-0031 allows remote attackers to execute arbitrary code using specially crafted ymsgr URIs.
5
When was CVE-2002-0031 disclosed?
CVE-2002-0031 was disclosed in early 2002.