help.yahoo.comConfirmation
http://help.yahoo.com/l/us/yahoo/widgets/security/security-08.html CVE-2007-4034
Yahoo! Widget < 4.0.5 - 'GetComponentVersion()' Remote Overflow
Record summary
CVE-2007-4034 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.
Description
Stack-based buffer overflow in the YDPCTL.YDPControl.1 (aka Yahoo! Installer Plugin for Widgets) ActiveX control before 2007.7.13.3 (20070620) in YDPCTL.dll in Yahoo! Widgets before 4.0.5 allows remote attackers to execute arbitrary code via a long argument to the GetComponentVersion method. NOTE: some of these details are obtained from third party information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBYahoo! Widget < 4.0.5 - 'GetComponentVersion()' Remote OverflowExploitDB exploitby lhoang8500Not analyzed1 file
References
837705vdb entry
http://osvdb.org/37705 26011Third-party advisory
http://secunia.com/advisories/26011 VU#120760Third-party advisory
http://www.kb.cert.org/vuls/id/120760 25086vdb entry
http://www.securityfocus.com/bid/25086 1018470vdb entry
http://www.securitytracker.com/id?1018470 ADV-2007-2679vdb entry
http://www.vupen.com/english/advisories/2007/2679 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-4034