The flaw is caused by a boundary error within the AudioConf ActiveX control (yacscom.dll), according to an advisory from Secunia.
The vulnerability can be exploited to cause a stack-based buffer overflow by setting the "socksHostname" and "hostname" properties to an overly large strong and then calling the "createAndJoinConference()" method, according to Secunia’s advisory.
The flaw exists in Yahoo Messenger versions 5, 6, 7 and 8, according to Secunia.
An advisory from TippingPoint’s Zero Day Initiative, which first disclosed the flaw to Yahoo last October, reported that user interaction is required to exploit the flaw, most commonly through a duped user visiting a malicious website.
Secunia today ranked the flaw as "highly critical," meaning that it can be exploited by arbitrary code.

Personetics Executive Forum 2026 — Sydney
Personetics Executive Forum 2026 — Auckland
Can Testing Keep Up? Quality in the Age of Accelerating Delivery
HPE Networking Day Sydney
iTnews Resilience, Rewired Breakfast



