Vulnerabilities in Yahoo protocol plugin

John Bailey rekkanoryo at
Sat Mar 5 14:16:50 EST 2011

On 03/05/2011 02:03 PM, John Bailey wrote:
> Hello, packagers,
> Marius Wachtler discovered three remote crash bugs in our Yahoo protocol
> handler.  All three of these are due to improper handling of malformed YMSG
> packets that are missing fields we expect to be present, causing NULL pointer
> dereferences.

I should have mentioned, these bugs have been present since libpurple 2.6.0.


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 836 bytes
Desc: OpenPGP digital signature
URL: <>

More information about the Packagers mailing list