RETIRED: Yahoo! Messenger Multiple Unspecified Remote Code Execution Vulnerabilities
Yahoo! Messenger is prone to multiple unspecified remote code-execution vulnerabilities.
No further details are currently available. We will update this BID as more information emerges.
Successfully exploiting these issues allows remote attackers to execute arbitrary machine code in the context of the affected application. This facilitates the remote compromise of affected computers.
Specific vulnerable versions of Yahoo! Messenger are not known, but versions in the 8 series for Microsoft Windows are reported affected.
UPDATE (June 7, 2007): The vendor announced that a fix is being developed to address this issue.
This BID has been replaced by the following writeups:
BID 24355 Yahoo! Messenger Webcam Viewer ActiveX Control Buffer Overflow Vulnerability
BID 24354 Yahoo! Messenger Webcam Upload ActiveX Control Buffer Overflow Vulnerability