help.yahoo.comConfirmation
http://help.yahoo.com/help/us/mesg/use/use-45.html CVE-2003-1129
Yahoo! Voice Chat ActiveX Control 1.0.0.43 - Remote Buffer Overflow
Record summary
CVE-2003-1129 has a selected CVSS score of 2.6; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in the Yahoo! Audio Conferencing (aka Voice Chat) ActiveX control before 1,0,0,45 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a URL with a long hostname to Yahoo! Messenger or Yahoo! Chat.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBYahoo! Voice Chat ActiveX Control 1.0.0.43 - Remote Buffer OverflowExploitDB exploitby cesaroNot analyzed1 file
References
78924Third-party advisory
http://secunia.com/advisories/8924 VU#272644Third-party advisory
http://www.kb.cert.org/vuls/id/272644 20030530 Yahoo! Security Advisory: Yahoo! Voice Chatmailing list
http://www.securityfocus.com/archive/1/323439 7561vdb entry
http://www.securityfocus.com/bid/7561 yahoo-audio-bo(12130)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/12130 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-1129