Yahoo! Assistant 3.6 - 'yNotifier.dll' ActiveX Control Memory Corruption



EKU-ID: 36694 CVE: CVE-2008-2111;OSVDB-44852 OSVDB-ID:
Author: Sowhat Published: 2008-05-06 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/29065/info

Yahoo! Assistant 'yNotifier.dll' ActiveX control is prone to a memory-corruption vulnerability.

Successfully exploiting this issue may allow remote attackers to execute arbitrary code in the context of the application using the affected ActiveX control. Failed exploit attempts will likely crash the application.

The issue affects Yahoo! Assistant 3.6 and prior versions.

<object classid='clsid:2283BB66-A15D-4AC8-BA72-9C8C9F5A1691'>