First published: Wed Dec 02 2009(Updated: )
An ActiveX control in YahooBridgeLib.dll for Yahoo! Messenger 9.0.0.2162, and possibly other 9.0 versions, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by calling the RegisterMe method with a long argument.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yahoo Messenger | =9.0.0.2162 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4171 is classified as a denial of service vulnerability that can cause application crashes.
To mitigate CVE-2009-4171, users should upgrade to a version of Yahoo! Messenger that is not affected by this vulnerability.
CVE-2009-4171 specifically affects Yahoo! Messenger version 9.0.0.2162 and potentially other versions in the 9.0.x series.
CVE-2009-4171 is caused by a NULL pointer dereference in the RegisterMe method of the YahooBridgeLib.dll ActiveX control.
Yes, CVE-2009-4171 allows remote attackers to exploit the vulnerability via a crafted call to the RegisterMe method.