Yahoo! Instant Messenger Plain Text Password Vulnerability
BID:4173
Info
Yahoo! Instant Messenger Plain Text Password Vulnerability
| Bugtraq ID: | 4173 |
| Class: | Design Error |
| CVE: |
CVE-2002-0322 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 22 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | Discovered by Chris Bisnett <[email protected]>. |
| Vulnerable: |
Yahoo! Messenger 4.0 |
| Not Vulnerable: |
Yahoo! Messenger 5.0 |
Discussion
Yahoo! Instant Messenger Plain Text Password Vulnerability
Yahoo! Messenger is the main client for Yahoo's instant messaging service.
It has been reported that Yahoo! Messenger version 4 does not encrypt the data transferred when a user is authenticating.
If a malicious third party could eavesdrop on network traffic between the messenger client and the Yahoo! server, this could potentially disclose, in plain text, the authentication information of a user.
Yahoo! Messenger is the main client for Yahoo's instant messaging service.
It has been reported that Yahoo! Messenger version 4 does not encrypt the data transferred when a user is authenticating.
If a malicious third party could eavesdrop on network traffic between the messenger client and the Yahoo! server, this could potentially disclose, in plain text, the authentication information of a user.
Exploit / POC
Yahoo! Instant Messenger Plain Text Password Vulnerability
No exploit code is required.
No exploit code is required.
Solution / Fix
Yahoo! Instant Messenger Plain Text Password Vulnerability
Solution:
Reportedly Yahoo! Messenger version 5 is not affected by this issue:
http://messenger.yahoo.com/
Solution:
Reportedly Yahoo! Messenger version 5 is not affected by this issue:
http://messenger.yahoo.com/
References
Yahoo! Instant Messenger Plain Text Password Vulnerability
References:
References: