CVE-2005-0242

The Audio Setup Wizard (asw.dll) in Yahoo! Messenger 6.0.0.1750, and possibly other versions, allows attackers to arbitrary code by placing a malicious ping.exe program into the Messenger program directory, which is installed with weak default permissions.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:yahoo:messenger:5.5:*:*:*:*:*:*:*
cpe:2.3:a:yahoo:messenger:5.6:*:*:*:*:*:*:*
cpe:2.3:a:yahoo:messenger:5.6.0.1351:*:*:*:*:*:*:*
cpe:2.3:a:yahoo:messenger:6.0:*:*:*:*:*:*:*
cpe:2.3:a:yahoo:messenger:6.0.0.1750:*:*:*:*:*:*:*

History

20 Nov 2024, 23:54

Type Values Removed Values Added
References () http://messenger.yahoo.com/security/update6.html - () http://messenger.yahoo.com/security/update6.html -
References () http://secunia.com/advisories/11815 - Patch () http://secunia.com/advisories/11815 - Patch
References () http://secunia.com/secunia_research/2004-6/advisory/ - Exploit, Patch, Vendor Advisory () http://secunia.com/secunia_research/2004-6/advisory/ - Exploit, Patch, Vendor Advisory

Information

Published : 2005-02-18 05:00

Updated : 2024-11-20 23:54


NVD link : CVE-2005-0242

Mitre link : CVE-2005-0242

CVE.ORG link : CVE-2005-0242


JSON object : View

Products Affected

yahoo

  • messenger