PT-2007-6123 · Yahoo · Yahoo! Messenger

Shinnai

·

Publicado

2007-09-20

·

Atualizado

2017-09-29

·

CVE-2007-5017

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Yahoo! Messenger version 8.1.0.421
Description A path traversal issue exists in the CYFT object in ft60.dll, allowing remote attackers to force a download and create or overwrite arbitrary files. This is achieved by providing a full pathname in the second argument to the GetFile method.
Recommendations For Yahoo! Messenger version 8.1.0.421, consider disabling the CYFT object in ft60.dll or restricting access to the GetFile method until a patch is available. Avoid using the GetFile method with untrusted input to minimize the risk of exploitation.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-5017

Produtos afetados

Yahoo! Messenger