发布时间 :2003-12-31 00:00:00
修订时间 :2008-09-05 16:36:08

[原文]Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send request (sendfile) with a large number of "%" (percent) characters after the Yahoo ID.

[CNNVD]Yahoo! Messenger文件传输缓冲区溢出漏洞(CNNVD-200312-393)

        Yahoo! Messenger 5.6版本存在缓冲区溢出漏洞。远程攻击者可以借助在Yahoo ID后添写超多"%"(百分号)的文件发送请求(sendfile)导致服务拒绝(崩溃)。

- CVSS (基础分值)

CVSS分值: 2.6 [轻微(LOW)]
机密性影响: NONE [对系统的机密性无影响]
完整性影响: NONE [不会对系统完整性产生影响]
可用性影响: PARTIAL [可能会导致性能下降或中断资源访问]
攻击复杂度: HIGH [漏洞利用存在特定的访问条件]
攻击向量: [--]
身份认证: NONE [漏洞利用无需身份认证]

- CPE (受影响的平台与产品)


- OVAL (用于检测的技术细节)


- 官方数据库链接
(官方数据源) MITRE
(官方数据源) NVD
(官方数据源) CNNVD

- 其它链接及资源
(UNKNOWN)  BID  8894
(UNKNOWN)  BUGTRAQ  20031026 Buffer Overflow in Yahoo messenger Client

- 漏洞信息

Yahoo! Messenger文件传输缓冲区溢出漏洞
低危 缓冲区溢出
2003-12-31 00:00:00 2005-10-20 00:00:00
        Yahoo! Messenger 5.6版本存在缓冲区溢出漏洞。远程攻击者可以借助在Yahoo ID后添写超多"%"(百分号)的文件发送请求(sendfile)导致服务拒绝(崩溃)。

- 公告与补丁

        Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: .

- 漏洞信息 (23293)

Yahoo! Messenger 5.6 File Transfer Buffer Overrun Vulnerability (EDBID:23293)
windows dos
2003-10-27 Verified
0 Hat-Squad Security Team
N/A [点击下载]
source: Yahoo! Messenger File Transfer Buffer Overrun Vulnerability

Yahoo! Messenger is prone to a remotely exploitable buffer overrun vulnerability. An attacker may trigger this condition by initiating a malformed 'sendfile' request, which the victim user must then accept. This will reportedly result in an access violation error, which is likely due to memory corruption.

An attacker may theoretically exploit this condition to execute arbitrary code on a client system. This condition can be exploited via a malicious 'sendfile' link. 


- 漏洞信息

Yahoo! Messenger Crafted File Transfer Remote Overflow DoS
Remote / Network Access Denial of Service, Input Manipulation
Loss of Integrity, Loss of Availability
Exploit Unknown

- 漏洞描述

Yahoo! Messenger contains a flaw that may allow a remote denial of service. The issue is triggered when a specially crafted file transfer occurs, and will result in loss of availability for the service.

- 时间线

2003-10-28 Unknow
Unknow Unknow

- 解决方案

Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by implementing the following workaround(s): Do not accept file transfers from unknown users.

- 相关参考

- 漏洞作者