PT-2007-6123 · Yahoo · Yahoo! Messenger
Shinnai
·
Published
2007-09-20
·
Updated
2017-09-29
·
CVE-2007-5017
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Yahoo! Messenger version 8.1.0.421
Description
A path traversal issue exists in the CYFT object in ft60.dll, allowing remote attackers to force a download and create or overwrite arbitrary files. This is achieved by providing a full pathname in the second argument to the
GetFile method.Recommendations
For Yahoo! Messenger version 8.1.0.421, consider disabling the CYFT object in ft60.dll or restricting access to the
GetFile method until a patch is available. Avoid using the GetFile method with untrusted input to minimize the risk of exploitation.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yahoo! Messenger