PT-2007-6123 · Yahoo · Yahoo! Messenger

Shinnai

·

Published

2007-09-20

·

Updated

2017-09-29

·

CVE-2007-5017

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Yahoo! Messenger version 8.1.0.421
Description A path traversal issue exists in the CYFT object in ft60.dll, allowing remote attackers to force a download and create or overwrite arbitrary files. This is achieved by providing a full pathname in the second argument to the GetFile method.
Recommendations For Yahoo! Messenger version 8.1.0.421, consider disabling the CYFT object in ft60.dll or restricting access to the GetFile method until a patch is available. Avoid using the GetFile method with untrusted input to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5017

Affected Products

Yahoo! Messenger