PT-2007-4431 · Yahoo · Yahoo! Messenger+1

Excepti0N

·

Published

2007-06-11

·

Updated

2018-10-16

·

CVE-2007-3148

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Yahoo! Messenger version 8.1.0.249
Description: A buffer overflow issue exists in the Yahoo! Webcam Viewer ActiveX control, allowing remote attackers to execute arbitrary code via a long server property value to the receive method.
Recommendations: For Yahoo! Messenger version 8.1.0.249, consider disabling the receive method in the Yahoo! Webcam Viewer ActiveX control until a patch is available.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-3148

Affected Products

Yahoo! Messenger
Yahoo! Webcam Viewer Activex Control