- Description
- The YMSGR URL handler in Yahoo! Messenger 5.x through 6.0 allows remote attackers to cause a denial of service (disconnect) via a room login or a room join request packet with a third : (colon) and an & (ampersand), which causes Messenger to send a corrupted packet to the server, which triggers a disconnect from the server.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:N/A:P
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:yahoo:messenger:5.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "349A209F-6609-4809-B228-E84623FA268D"
},
{
"criteria": "cpe:2.3:a:yahoo:messenger:5.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "92465439-530F-435E-976F-491AD3C56944"
},
{
"criteria": "cpe:2.3:a:yahoo:messenger:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F8EE7278-FFAD-489B-BDCC-BF6BA8D5DF0C"
}
],
"operator": "OR"
}
]
}
]