CVE-2007-1680: Buffer Overflow
Published Apr 6, 2007
·Updated
Stack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger before 20070313 allows remote attackers to execute arbitrary code via long (1) socksHostname and (2) hostname properties.
Affected Software
5 affected components
Yahoo Messenger=8.1.0.239
Yahoo Messenger=8.0
Yahoo Messenger=8.0_2005.1.1.4
Yahoo Messenger=8.1.0.209
Yahoo Messenger=8.0.0.863
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Apr 6, 2007
CVE Published
01:19 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1680?
CVE-2007-1680 has a severity rating that indicates a critical risk of remote code execution.
2
How do I fix CVE-2007-1680?
To fix CVE-2007-1680, update Yahoo Messenger to version 8.1.0.239 or newer.
3
What software is affected by CVE-2007-1680?
CVE-2007-1680 affects Yahoo Messenger versions 8.0 and 8.1.0.239 and earlier.
4
What type of attack does CVE-2007-1680 exploit?
CVE-2007-1680 exploits a stack-based buffer overflow vulnerability.
5
Can CVE-2007-1680 be exploited remotely?
Yes, CVE-2007-1680 can be exploited by remote attackers through the affected ActiveX control.