Content
JS/Exploit-YahooGrid
- Type
- Trojan
- SubType
- Exploit
- Discovery Date
- 02/05/2008
- Length
- varies
- Minimum DAT
- 5223 (02/05/2008)
- Updated DAT
- 5224 (02/06/2008)
- Minimum Engine
- 5.1.00
- Description Added
- 02/05/2008
- Description Modified
- 02/05/2008 6:16 AM (PT)
Tab Navigation
Characteristics
JS/Exploit-YahooGrid is a generic detection for YMPDataGrid (datagrid.dll) and YMGMediaGridAx (mediagridax.dll) ActiveX controls buffer overflow vulnerability in Yahoo! Music Jukebox and Yahoo! Messenger.
The buffer overflow vulnerabilities occurs while supplying a long string to the AddImage, AddButton or AddBitmap functions. This vulnerability could be exploited by a malicious user to cause remote code execution.
Symptoms
This detection is sufficiently generic, such that it can cover a number of threats that contain the exploit code. Therefore, it is not possible to describe specific symptoms or details about system changes that can occur from this threat. However, simply seeing this detection does not mean that any exploit code was run at all as such exploit code could only run on a vulnerable system.
Additionally some exploits simply cause Internet Explorer to crash and nothing more.
Method of Infection
This threat could be delivered via an email message, IM or an infectious web page.
Removal
A combination of the latest DATs and the Engine will be able to detect and remove this threat. AVERT recommends users not to trust seemingly familiar or safe file icons, particularly when received via P2P clients, IRC, email or other media where users can share files.
Variants
Variants
N/A
All Information
Overview -
JS/Exploit-YahooGrid is a generic detection for YMPDataGrid (datagrid.dll) and YMGMediaGridAx (mediagridax.dll) ActiveX controls buffer overflow vulnerability in Yahoo! Music Jukebox and Yahoo! Messenger.
Characteristics
Characteristics -
JS/Exploit-YahooGrid is a generic detection for YMPDataGrid (datagrid.dll) and YMGMediaGridAx (mediagridax.dll) ActiveX controls buffer overflow vulnerability in Yahoo! Music Jukebox and Yahoo! Messenger.
The buffer overflow vulnerabilities occurs while supplying a long string to the AddImage, AddButton or AddBitmap functions. This vulnerability could be exploited by a malicious user to cause remote code execution.
Symptoms
Symptoms -
This detection is sufficiently generic, such that it can cover a number of threats that contain the exploit code. Therefore, it is not possible to describe specific symptoms or details about system changes that can occur from this threat. However, simply seeing this detection does not mean that any exploit code was run at all as such exploit code could only run on a vulnerable system.
Additionally some exploits simply cause Internet Explorer to crash and nothing more.
Method of Infection
Method of Infection -
This threat could be delivered via an email message, IM or an infectious web page.
Removal -
Removal -
A combination of the latest DATs and the Engine will be able to detect and remove this threat. AVERT recommends users not to trust seemingly familiar or safe file icons, particularly when received via P2P clients, IRC, email or other media where users can share files.
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A