Yahoo! Messenger Spoofed Username

medium Nessus Network Monitor Plugin ID 1265

Synopsis

The remote host is running software which allows spoofed communications

Description

The remote host is running Yahoo Instant Messenger. Reportedly, in version 5.0 of Instant Messenger a user can spoof his or her username. A remote attacker can use this future to flood a victim with messages without being identified.

Solution

Upgrade to the latest version of Yahoo Instant Messenger.

Plugin Details

Severity: Medium

ID: 1265

Published: 8/20/2004

Updated: 3/6/2019

Risk Information

VPR

Risk Factor: Low

Score: 3.4

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Temporal Vector: CVSS:3.0/E:H/RL:U/RC:X

Vulnerability Information

CPE: cpe:/a:yahoo:messenger

Reference Information

CVE: CVE-2002-0321

BID: 4164