what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

secres18022005-1.txt

secres18022005-1.txt
Posted Feb 25, 2005
Authored by Andreas Sandblad | Site secunia.com

Secunia Research Advisory - Secunia Research has discovered a vulnerability in Yahoo! Messenger, which can be exploited by malicious people to trick users into executing malicious files.

tags | advisory
advisories | CVE-2005-0243
SHA-256 | 513774c469defad1cd93cfb1ccb109ae36b76b727993df1dca8cea05c194fcad

secres18022005-1.txt

Change Mirror Download
======================================================================

Secunia Research 18/02/2005

- Yahoo! Messenger File Transfer Filename Spoofing -

======================================================================
Table of Contents

Affected Software....................................................1
Severity.............................................................2
Description of Vulnerability.........................................3
Solution.............................................................4
Time Table...........................................................5
Credits..............................................................6
References...........................................................7
About Secunia........................................................8
Verification.........................................................9

======================================================================
1) Affected Software

Yahoo! Messenger 6.0.0.1750

Other versions may also be affected.

======================================================================
2) Severity

Rating: Less critical
Impact: Spoofing
Where: From remote

======================================================================
3) Description of Vulnerability

Secunia Research has discovered a vulnerability in Yahoo! Messenger,
which can be exploited by malicious people to trick users into
executing malicious files.

The problem is that files with long filenames are not displayed
correctly in the file transfer dialogs. This can be exploited to
trick users into accepting and potentially executing malicious files.

Details:
Yahoo! Messenger wraps overly long filenames and shows only the first
line of the filename in the file transfer dialogs. The file extension
can thus be spoofed for a filename containing a whitespace and two
file extensions.

Successful exploitation requires that the option
"Hide extension for known file types" is enabled in Windows
(default setting).

The vulnerability has been confirmed in version 6.0.0.1750. Other
versions may also be affected.

======================================================================
4) Solution

Update to version 6.0.0.1921.
http://messenger.yahoo.com/

======================================================================
5) Time Table

04/01/2005 - Vulnerability discovered.
10/01/2005 - Vendor notified.
19/01/2005 - Vendor confirms the vulnerability.
17/02/2005 - Vendor issued fixed version.
18/02/2005 - Public disclosure.

======================================================================
6) Credits

Discovered by Andreas Sandblad, Secunia Research.

======================================================================
7) References

The Common Vulnerabilities and Exposures (CVE) project has assigned
candidate number CAN-2005-0243 for the vulnerability.

======================================================================
8) About Secunia

Secunia collects, validates, assesses, and writes advisories regarding
all the latest software vulnerabilities disclosed to the public. These
advisories are gathered in a publicly available database at the
Secunia web site:

http://secunia.com/

Secunia offers services to our customers enabling them to receive all
relevant vulnerability information to their specific system
configuration.

Secunia offers a FREE mailing list called Secunia Security Advisories:

http://secunia.com/secunia_security_advisories/

======================================================================
9) Verification

Please verify this advisory by visiting the Secunia web site:
http://secunia.com/secunia_research/2005-2/advisory/

======================================================================


Login or Register to add favorites

File Archive:

June 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jun 1st
    0 Files
  • 2
    Jun 2nd
    0 Files
  • 3
    Jun 3rd
    18 Files
  • 4
    Jun 4th
    21 Files
  • 5
    Jun 5th
    0 Files
  • 6
    Jun 6th
    57 Files
  • 7
    Jun 7th
    6 Files
  • 8
    Jun 8th
    0 Files
  • 9
    Jun 9th
    0 Files
  • 10
    Jun 10th
    12 Files
  • 11
    Jun 11th
    27 Files
  • 12
    Jun 12th
    38 Files
  • 13
    Jun 13th
    16 Files
  • 14
    Jun 14th
    14 Files
  • 15
    Jun 15th
    0 Files
  • 16
    Jun 16th
    0 Files
  • 17
    Jun 17th
    0 Files
  • 18
    Jun 18th
    0 Files
  • 19
    Jun 19th
    0 Files
  • 20
    Jun 20th
    0 Files
  • 21
    Jun 21st
    0 Files
  • 22
    Jun 22nd
    0 Files
  • 23
    Jun 23rd
    0 Files
  • 24
    Jun 24th
    0 Files
  • 25
    Jun 25th
    0 Files
  • 26
    Jun 26th
    0 Files
  • 27
    Jun 27th
    0 Files
  • 28
    Jun 28th
    0 Files
  • 29
    Jun 29th
    0 Files
  • 30
    Jun 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close