Harold, speaking of.......  ;-)  (One of things I alluded to a 
couple of days ago).
-Clint


TITLE:
Yahoo! Messenger Denial of Service Weakness

SECUNIA ADVISORY ID:
SA20773

VERIFY ADVISORY:
http://secunia.com/advisories/20773/

CRITICAL:
Not critical

IMPACT:
DoS

WHERE:
>From remote

SOFTWARE:
Yahoo! Messenger 7.x
http://secunia.com/product/5956/

DESCRIPTION:
A weakness in Yahoo! Messenger, which potentially can be 
exploited by malicious people to cause a DoS (Denial of 
Service).

The weakness is caused due to an error within the handling of 
certain
messages. This can be exploited to crash another user's Yahoo!
Messenger client via a specially crafted message that contains 
a
non-ascii character.

For example:
s:[space]msg[alt+0160]:---------------------------------------------iframe
onload=$InlineAction()>:)

Successful exploitation requires that the user has not 
configured the
application to ignore malicious users that are not on his 
Messenger
list.

The weakness has been confirmed in version 7.5.0.814. Other 
versions
may also be affected.

SOLUTION:
Configure Yahoo! Messenger to ignore users that are not in the
Messenger list.
============= PCWorks Mailing List =================
Don't see your post? Check our posting guidelines &
make sure you've followed proper posting procedures,
http://pcworkers.com/rules.htm
Contact list owner <[EMAIL PROTECTED]>
Unsubscribing and other changes: http://pcworkers.com
=====================================================

Reply via email to