First published: Fri Aug 31 2007(Updated: )
Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1.0.419 allows remote attackers to execute arbitrary code via unspecified vectors involving arguments to the (1) fvCom and (2) info methods. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yahoo Messenger | <=8.1.0.413 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4515 has a high severity rating due to its potential for remote code execution.
CVE-2007-4515 exploits a buffer overflow vulnerability in the YVerInfo.dll ActiveX control.
CVE-2007-4515 affects Yahoo Messenger versions up to and including 8.1.0.413.
To fix CVE-2007-4515, update Yahoo Messenger to version 8.1.0.419 or later.
Exploiting CVE-2007-4515 may allow attackers to execute arbitrary code on the affected system.