CVE-2007-1680 Information
Description
Stack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger before 20070313 allows remote attackers to execute arbitrary code via long (1) socksHostname and (2) hostname properties.
Reference
http://messenger.yahoo.com/security_update.php?id=031207 http://osvdb.org/34319 http://secunia.com/advisories/24742 http://securityreason.com/securityalert/2523 http://www.kb.cert.org/vuls/id/388377 http://www.securityfocus.com/archive/1/464607/100/0/threaded http://www.securityfocus.com/bid/23291 http://www.securitytracker.com/id?1017867 http://www.vupen.com/english/advisories/2007/1219 http://www.zerodayinitiative.com/advisories/ZDI-07-012.html https://exchange.xforce.ibmcloud.com/vulnerabilities/33408
Share on: