Description: Two vulnerabilities have been identified in Yahoo! Chat and Messenger possibly allowing malicious people to execute arbitrary code through HTML documents.
The problem is that the "TargetName" parameter isn't properly verified in Yahoo! Webcam Viewer Wrapper ActiveX control. This can be exploited to cause both a stack and a heap based overflow which possibly could lead to execution of arbitrary code.
Another problem has been identified in the handling of the "AppId" parameter in the YInstStarter ActiveX control. This may be exploited to cause a heap overflow which could lead to execution of arbitrary code.
Solution: Remove all Yahoo! ActiveX controls and reinstall the software from Yahoo!.
The following page will try to detect if you are vulnerable and upgrade your ActiveX control's.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.