Yahoo! Messenger < 6.0.0.1921 Multiple DoS

Low Nessus Network Monitor Plugin ID 2681

Synopsis

The remote host is vulnerable to a Denial of Service (DoS) attack.

Description

The remote host is running a version of Yahoo Instant Messenger that is reported vulnerable to a remote buffer overflow. An attacker exploiting this flaw would craft a malicious 'away' message and then entice an unsuspecting user to attempt to contact them. When the user receives the malicious 'away' message, the overflow would be triggered and code would be executed remotely. In addition, this version of Yahoo! Messenger is vulnerable to a remote Denial of Service (DoS) attack via a malformed YMSGR: URI.

Solution

Upgrade to version 6.0.0.1921 or higher.

Plugin Details

Severity: Low

ID: 2681

Published: 2005/03/08

Modified: 2016/02/05

Dependencies: 1273, 1275

Risk Information

Risk Factor: Low

CVSSv2

Base Score: 2.9

Temporal Score: 2.8

Vector: CVSS2#AV:A/AC:M/Au:N/C:N/I:N/A:P

Temporal Vector: CVSS2#E:H/RL:W/RC:ND

CVSSv3

Base Score: 3

Temporal Score: 2.9

Vector: CVSS3#AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Temporal Vector: CVSS3#E:H/RL:W/RC:X

Vulnerability Information

CPE: cpe:/a:yahoo:messenger

Reference Information

CVE: CVE-2005-0737, CVE-2005-1618

BID: 13626, 12750