First published: Fri Sep 11 2015(Updated: )
Multiple stack-based buffer overflows in Yahoo! Messenger 11.5.0.228 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the (1) shortcut or (2) title keys in an emoticons.xml file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yahoo Messenger | <=11.5.0.228 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-7216 is rated as a high severity vulnerability due to the potential for remote code execution and denial of service.
To address CVE-2014-7216, upgrade Yahoo Messenger to version 11.5.0.229 or later.
CVE-2014-7216 affects Yahoo Messenger version 11.5.0.228 and earlier.
CVE-2014-7216 allows attackers to exploit buffer overflows leading to denial of service and potentially arbitrary code execution.
Currently, the best workaround for CVE-2014-7216 is to uninstall Yahoo Messenger if immediate upgrade is not feasible.