Buffer Overflow in AudioConf ActiveX Control of Yahoo! Messenger
CVE-2007-1680

Currently unrated

Key Information:

Vendor

Yahoo

Status
Vendor
CVE Published:
6 April 2007

What is CVE-2007-1680?

The AudioConf ActiveX control in Yahoo! Messenger versions prior to March 13, 2007, contains a stack-based buffer overflow vulnerability in its createAndJoinConference function. This flaw can be exploited by remote attackers through crafted inputs provided to the socksHostname and hostname properties, potentially allowing the execution of arbitrary code on the victim's machine. Users are advised to update to the latest version of Yahoo! Messenger to remediate this vulnerability.

References

EPSS Score

8% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.