HTTP: Yahoo Toolbar URL Shortcut Buffer Overflow

This signature detects attempts to exploit a known vulnerability in Yahoo! Toolbar URL Shortcut ActiveX Control. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX calls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

YShortcut is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input. An attacker can exploit this issue to execute arbitrary code in the context of an application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions. Yahoo! Toolbar 1.4.1 is vulnerable to this issue; other versions may also be affected.

Affected Products

Yahoo! toolbar

Short Name
HTTP:STC:ACTIVEX:YSHORTCUT
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Buffer CVE-2007-6535 Overflow Shortcut Toolbar URL Yahoo bid:26956
Release Date
01/21/2008
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3724
False Positive
Unknown
Vendors

Yahoo!

CVSS Score

6.8

Found a potential security threat?