First published: Tue Jul 10 2007(Updated: )
Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users, who are listed in an address book, to execute arbitrary code via unspecified vectors, aka ZD-00000005. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yahoo Messenger | =8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3638 is classified as a high-severity vulnerability due to its potential to allow remote code execution.
To mitigate CVE-2007-3638, users should update to a more secure version of Yahoo Messenger or discontinue its use.
CVE-2007-3638 affects users of Yahoo Messenger version 8.1 who have malicious authenticated contacts in their address book.
CVE-2007-3638 is a buffer overflow vulnerability that can lead to arbitrary code execution.
CVE-2007-3638 requires user assistance for exploitation, as it can only be triggered by interactions with compromised contacts.