Release DateJun 11, 2007 |
Severitylow |
ImpactSystem compromise, remote code execution. |
DescriptionThe Yahoo! Webcam ActiveX Control has multiple buffer overflow vulnerabilities. A remote attacker could execute arbitrary code on a vulnerable system via a malformed web page. |
Affected ProductsYahoo! Messenger version 8.1.0.249 and prior. |
Recommended ActionsUpgrade to the latest version, available from the web site.http://messenger.yahoo.com/download.php |
Coverage IPS
VCM |
Common Vulnerabilities and Exposures (CVE)CVE-2007-3147CVE-2007-3148 |
Reference/shttp://www.securityfocus.com/bid/24341 (BugTraq)http://www.securityfocus.com/bid/24354 (BugTraq) http://www.securityfocus.com/bid/24355 (BugTraq) http://www.frsirt.com/english/advisories/2007/2094 (FrSIRT) |