Harold, speaking of....... ;-) (One of things I alluded to a couple of days ago). -Clint
TITLE: Yahoo! Messenger Denial of Service Weakness SECUNIA ADVISORY ID: SA20773 VERIFY ADVISORY: http://secunia.com/advisories/20773/ CRITICAL: Not critical IMPACT: DoS WHERE: >From remote SOFTWARE: Yahoo! Messenger 7.x http://secunia.com/product/5956/ DESCRIPTION: A weakness in Yahoo! Messenger, which potentially can be exploited by malicious people to cause a DoS (Denial of Service). The weakness is caused due to an error within the handling of certain messages. This can be exploited to crash another user's Yahoo! Messenger client via a specially crafted message that contains a non-ascii character. For example: s:[space]msg[alt+0160]:---------------------------------------------iframe onload=$InlineAction()>:) Successful exploitation requires that the user has not configured the application to ignore malicious users that are not on his Messenger list. The weakness has been confirmed in version 7.5.0.814. Other versions may also be affected. SOLUTION: Configure Yahoo! Messenger to ignore users that are not in the Messenger list. ============= PCWorks Mailing List ================= Don't see your post? Check our posting guidelines & make sure you've followed proper posting procedures, http://pcworkers.com/rules.htm Contact list owner <[EMAIL PROTECTED]> Unsubscribing and other changes: http://pcworkers.com =====================================================
