Buffer overflow in a certain ActiveX control in YVerInfo.dll before...
Vulnerability Description
Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1.0.419 allows remote attackers to execute arbitrary code via unspecified vectors involving arguments to the (1) fvCom and (2) info methods. NOTE: some of these details are obtained from third party information.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-4515
Credits & Attribution
No credits recorded in the NVD database.
References
- http://osvdb.org/37739
- http://secunia.com/advisories/26579
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36363
- http://messenger.yahoo.com/security_update.php?id=082907
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=591
- http://securityreason.com/securityalert/3083
- http://securitytracker.com/id?1018628
- http://www.securityfocus.com/bid/25494
- http://www.vupen.com/english/advisories/2007/3011
More from yahoo
View All →Affected Vendor
yahoo
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.