First published: Tue Dec 31 2002(Updated: )
Yahoo! Messenger before February 2002 allows remote attackers to add arbitrary users to another user's buddy list and possibly obtain sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yahoo Messenger | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2002-1664 is considered moderate due to the potential for unauthorized access to buddy lists.
To fix CVE-2002-1664, upgrade to a version of Yahoo! Messenger released after February 2002.
Users of Yahoo! Messenger version 5.0 prior to February 2002 are affected by CVE-2002-1664.
CVE-2002-1664 is associated with a remote attack that allows the addition of arbitrary users to another user's buddy list.
CVE-2002-1664 could potentially allow attackers to obtain sensitive information from the affected user's buddy list.