Stack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger before 20070313 allows remote attackers to execute arbitrary code via long (1) socksHostname and (2) hostname properties.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/33408 | vdb entry |
http://www.securityfocus.com/bid/23291 | patch vendor advisory vdb entry |
http://secunia.com/advisories/24742 | patch vendor advisory third party advisory |
http://www.kb.cert.org/vuls/id/388377 | third party advisory us government resource |
http://www.zerodayinitiative.com/advisories/ZDI-07-012.html | patch vendor advisory |
http://securityreason.com/securityalert/2523 | third party advisory |
http://www.vupen.com/english/advisories/2007/1219 | vdb entry |
http://osvdb.org/34319 | vdb entry |
http://www.securitytracker.com/id?1017867 | vdb entry |
http://messenger.yahoo.com/security_update.php?id=031207 | patch |
http://www.securityfocus.com/archive/1/464607/100/0/threaded | mailing list |