Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Security Alerts and vulnerabilities Lets keep abreast on the latest threats by posting those findings here..

Reply
 
Thread Tools Display Modes
  #1  
Old 02-24-2005, 06:45 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,575
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
Yahoo! Messenger is "a free instant messaging service that you can use to communicate with other people who also use Yahoo! Messenger".

Yahoo! Messenger contains multiple vulnerabilities with the file transfer spoofing, and with audio setup wizard privilege escalation.

Vulnerable Systems:
* Yahoo! Messenger version 6.0.0.1750 (for Windows)

Immune Systems:
* Yahoo! Messenger version 6.0.0.1921 (for Windows) or newer

Audio Setup Wizard Privilege Escalation
Yahoo! Messenger contains a vulnerability which can be exploited by malicious, local users to gain escalated privileges.

The vulnerability is caused due to a combination of weak default directory permissions and the Audio Setup Wizard (asw.dll) invoking the "ping.exe" utility insecurely during the connection testing phase. This can be exploited to execute arbitrary code with the privileges of another user by placing a malicious "ping.exe" file in the application's "Messenger" directory.

Successful exploitation requires that a user runs the Audio Setup Wizard and that the application has been installed in a non-default location (not as a subdirectory to the "Program Files" directory).

File Transfer Filename Spoofing
Yahoo! Messenger wraps overly long filenames and shows only the first line of the filename in the file transfer dialogs. The file extension can thus be spoofed for a filename containing a whitespace and two file extensions.

Successful exploitation requires that the option "Hide extension for known file types" is enabled in Windows (default setting).

No update has been issued as of yet but watch for one in the very near future.
Reply With Quote
Posted


Reply

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Multiple Vulnerabilities in Mozilla Firefox, Netscape Mobo Security Alerts and vulnerabilities 0 09-23-2005 08:56 PM
Real Player vulnerabilities Mobo Security Alerts and vulnerabilities 0 03-02-2005 07:11 PM
Mozilla / Firefox Three Vulnerabilities Mobo Security Alerts and vulnerabilities 0 02-08-2005 11:16 AM
Adobe Reader / Adobe Acrobat Multiple Vulnerabilit Mobo Security Alerts and vulnerabilities 0 12-19-2004 12:56 PM
Web Forums Server Multiple Vulnerabilities Mobo Security Alerts and vulnerabilities 0 11-03-2004 07:23 AM



All times are GMT -5. The time now is 05:27 PM.


Firefox 2