PT-2002-2388 · Yahoo · Yahoo! Messenger
Published
2002-12-31
·
Updated
2016-10-18
·
CVE-2002-1664
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Yahoo! Messenger versions prior to February 2002
Description
The issue allows remote attackers to add arbitrary users to another user's buddy list, which could lead to obtaining sensitive information.
Recommendations
For versions prior to February 2002, update to a version released after February 2002 to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Yahoo! Messenger