First published: Wed Dec 31 2003(Updated: )
Buffer overflow in the Yahoo! Audio Conferencing (aka Voice Chat) ActiveX control before 1,0,0,45 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a URL with a long hostname to Yahoo! Messenger or Yahoo! Chat.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yahoo Audio Conferencing Activex Control | =1.0.0.43 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1129 has a high severity rating due to the potential for remote code execution and denial of service.
To fix CVE-2003-1129, update the Yahoo! Audio Conferencing ActiveX control to version 1.0.0.45 or later.
The potential impacts of CVE-2003-1129 include system crashes and unauthorized execution of malicious code.
Users of Yahoo! Audio Conferencing ActiveX control versions prior to 1.0.0.45 are primarily affected by CVE-2003-1129.
Yes, CVE-2003-1129 can be exploited remotely by sending a specially crafted URL with a long hostname.