CVE-2012-0268: Buffer Overflow
Integer overflow in the CYImage::LoadJPG method in YImage.dll in Yahoo! Messenger before 11.5.0.155, when photo sharing is enabled, might allow remote attackers to execute arbitrary code via a crafted JPG image that triggers a heap-based buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0268?
CVE-2012-0268 is considered a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2012-0268?
To fix CVE-2012-0268, update Yahoo Messenger to version 11.5.0.155 or later where the vulnerability has been patched.
Which versions of Yahoo Messenger are affected by CVE-2012-0268?
CVE-2012-0268 affects Yahoo Messenger versions prior to 11.5.0.155.
What type of vulnerability is CVE-2012-0268?
CVE-2012-0268 is an integer overflow vulnerability leading to a heap-based buffer overflow.
Can CVE-2012-0268 be exploited through image files?
Yes, CVE-2012-0268 can be exploited by sending a specially crafted JPG image to a vulnerable version of Yahoo Messenger.