CVE-2009-4171: Buffer Overflow
An ActiveX control in YahooBridgeLib.dll for Yahoo! Messenger 9.0.0.2162, and possibly other 9.0 versions, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by calling the RegisterMe method with a long argument.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4171?
CVE-2009-4171 is classified as a denial of service vulnerability that can cause application crashes.
How do I fix CVE-2009-4171?
To mitigate CVE-2009-4171, users should upgrade to a version of Yahoo! Messenger that is not affected by this vulnerability.
What software is affected by CVE-2009-4171?
CVE-2009-4171 specifically affects Yahoo! Messenger version 9.0.0.2162 and potentially other versions in the 9.0.x series.
What is the cause of CVE-2009-4171?
CVE-2009-4171 is caused by a NULL pointer dereference in the RegisterMe method of the YahooBridgeLib.dll ActiveX control.
Can CVE-2009-4171 be exploited remotely?
Yes, CVE-2009-4171 allows remote attackers to exploit the vulnerability via a crafted call to the RegisterMe method.