Stack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger before 20070313 allows remote attackers to execute arbitrary code via long (1) socksHostname and (2) hostname properties.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:28
Type | Values Removed | Values Added |
---|---|---|
References | () http://messenger.yahoo.com/security_update.php?id=031207 - Patch | |
References | () http://osvdb.org/34319 - | |
References | () http://secunia.com/advisories/24742 - Patch, Vendor Advisory | |
References | () http://securityreason.com/securityalert/2523 - | |
References | () http://www.kb.cert.org/vuls/id/388377 - US Government Resource | |
References | () http://www.securityfocus.com/archive/1/464607/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/23291 - Patch, Vendor Advisory | |
References | () http://www.securitytracker.com/id?1017867 - | |
References | () http://www.vupen.com/english/advisories/2007/1219 - | |
References | () http://www.zerodayinitiative.com/advisories/ZDI-07-012.html - Patch, Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/33408 - |
Information
Published : 2007-04-06 01:19
Updated : 2024-11-21 00:28
NVD link : CVE-2007-1680
Mitre link : CVE-2007-1680
CVE.ORG link : CVE-2007-1680
JSON object : View
Products Affected
yahoo
- messenger
CWE