Yahoo! Messenger Message Handling Denial of Service Vulnerability
BID:18622
CVE-2006-3298 |Info
Yahoo! Messenger Message Handling Denial of Service Vulnerability
| Bugtraq ID: | 18622 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-3298 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 23 2006 12:00AM |
| Updated: | Feb 20 2007 08:27PM |
| Credit: | Ivan Ivan is credited with the discovery of this vulnerability. |
| Vulnerable: |
Yahoo! Messenger 7.5 .814 Yahoo! Messenger 7.0 .438 |
| Not Vulnerable: |
Yahoo! Messenger 8.1.0.239 Yahoo! Messenger 8.1.0.209 |
Discussion
Yahoo! Messenger Message Handling Denial of Service Vulnerability
Yahoo! Messenger is prone to a denial-of-service vulnerability. Successful exploitation will cause the application to crash, effectively denying service.
This issue affects version 7.5.0.814; other versions may also be vulnerable.
Yahoo! Messenger is prone to a denial-of-service vulnerability. Successful exploitation will cause the application to crash, effectively denying service.
This issue affects version 7.5.0.814; other versions may also be vulnerable.
Exploit / POC
Yahoo! Messenger Message Handling Denial of Service Vulnerability
An attacker can exploit this issue via standard networking tools or possibly by using another client application.
The following examples are sufficient to trigger this issue:
s:[space]msg[alt+0160]:---------------------------------------------iframe onload=$InlineAction()>:)
msg:---------------------------------------------iframe onload=$InlineAction()>:)
An attacker can exploit this issue via standard networking tools or possibly by using another client application.
The following examples are sufficient to trigger this issue:
s:[space]msg[alt+0160]:---------------------------------------------iframe onload=$InlineAction()>:)
msg:---------------------------------------------iframe onload=$InlineAction()>:)
Solution / Fix
Yahoo! Messenger Message Handling Denial of Service Vulnerability
Solution:
frisky chris <[email protected]> states that this issue does not affect version 8.1 of Yahoo! Messenger. Symantec has not confirmed this.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
frisky chris <[email protected]> states that this issue does not affect version 8.1 of Yahoo! Messenger. Symantec has not confirmed this.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
Yahoo! Messenger Message Handling Denial of Service Vulnerability
References:
References:
- Yahoo! Messenger Homepage (Yahoo!)