·¢²¼ÈÕÆÚ£º2006-12-15
¸üÐÂÈÕÆÚ£º2006-12-18
ÊÜÓ°Ïìϵͳ£º
Yahoo! Messenger <= 8.0.0.863
ÃèÊö£º
BUGTRAQ ID:
21607ÑÅ»¢Í¨ÊÇÒ»¿î·Ç³£Á÷Ðеļ´Ê±Í¨Ñ¶¹¤¾ß¡£
ÑÅ»¢Í¨µÄymmapi.dllÎļþËùÌṩµÄYMailAttach ActiveX¿Ø¼þÖдæÔÚ»º³åÇøÒç³ö£¬Ô¶³Ì¹¥»÷Õß¿ÉÄÜÀûÓôË©¶´ÔÚÓû§»úÆ÷ÉÏÖ´ÐÐÈÎÒâÖ¸Áî¡£
Èç¹ûÓû§ÊÜÆä¯ÀÀÁ˶ñÒâµÄHTMLÎĵµµÄ»°£¬¾Í»á´¥·¢Õâ¸öÒç³ö£¬µ¼ÖÂÖ´ÐÐÈÎÒâÖ¸Áî»òµ¼ÖÂInternet Explorer±ÀÀ£¡£
<*À´Ô´£ºYahoo
Á´½Ó£º
http://secunia.com/advisories/23401/ http://messenger.yahoo.com/security_update.php?id=120806 http://www.kb.cert.org/vuls/id/901852*>
½¨Ò飺
ÁÙʱ½â¾ö·½·¨£º
* ÔÚIEÖнûÓÃYMailAttach ActiveX¿Ø¼þ¡£½«ÒÔÏÂÎı¾±£´æÎª.REGÎļþ²¢µ¼È룺
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{AA218328-0EA8-4D70-8972-E987A9190FF4}]
"Compatibility Flags"=dword:00000400
* ½ûÓÃActiveX¿Ø¼þ¡£
³§É̲¹¶¡£º
Yahoo!
------
Ŀǰ³§ÉÌÒѾ·¢²¼ÁËÉý¼¶²¹¶¡ÒÔÐÞ¸´Õâ¸ö°²È«ÎÊÌ⣬Çëµ½³§É̵ÄÖ÷Ò³ÏÂÔØ£º
http://messenger.yahoo.com/