PT-2007-4431 · Yahoo · Yahoo! Messenger+1
Excepti0N
·
Published
2007-06-11
·
Updated
2018-10-16
·
CVE-2007-3148
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Yahoo! Messenger version 8.1.0.249
Description:
A buffer overflow issue exists in the Yahoo! Webcam Viewer ActiveX control, allowing remote attackers to execute arbitrary code via a long server property value to the
receive method.Recommendations:
For Yahoo! Messenger version 8.1.0.249, consider disabling the
receive method in the Yahoo! Webcam Viewer ActiveX control until a patch is available.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yahoo! Messenger
Yahoo! Webcam Viewer Activex Control