Risk: High
A highly critical buffer overflow vulnerability has been discovered in Yahoo! Messenger, which if successfully exploited, could result in system compromise.
The vulnerability occurs due to a boundary error within the AudioConf ActiveX control (yacscom.dll) component of Yahoo! Messenger. By setting the "socksHostname" and "hostName" properties to an overly large string and subsequently calling the "createAndJoinConference()" method, the vulnerability can be exploited to cause a stack-based buffer overflow.
Yahoo! has issued a security update urging users to upgrade, which is available at:
http://messenger.yahoo.com/security_update.php?id=031207