CVE-2005-0242: Medium severity Yahoo Messenger vulnerability
The Audio Setup Wizard (asw.dll) in Yahoo! Messenger 6.0.0.1750, and possibly other versions, allows attackers to arbitrary code by placing a malicious ping.exe program into the Messenger program directory, which is installed with weak default permissions.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0242?
CVE-2005-0242 is considered to have a high severity due to its potential to allow attackers to execute arbitrary code.
How do I fix CVE-2005-0242?
To fix CVE-2005-0242, ensure that vulnerable versions of Yahoo Messenger are not used and consider updating to a patched version.
Which versions of Yahoo Messenger are affected by CVE-2005-0242?
CVE-2005-0242 affects Yahoo Messenger versions 5.5, 5.6, and 6.0.0.1750.
What type of vulnerability is CVE-2005-0242?
CVE-2005-0242 is a code execution vulnerability that can be exploited via weak permissions on the Messenger program directory.
Can CVE-2005-0242 be exploited remotely?
Yes, CVE-2005-0242 can be exploited remotely if the attacker can place a malicious ping.exe in the Yahoo Messenger directory.