First published: Fri Feb 18 2005(Updated: )
The Audio Setup Wizard (asw.dll) in Yahoo! Messenger 6.0.0.1750, and possibly other versions, allows attackers to arbitrary code by placing a malicious ping.exe program into the Messenger program directory, which is installed with weak default permissions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yahoo Messenger | =5.6 | |
Yahoo Messenger | =6.0.0.1750 | |
Yahoo Messenger | =5.5 | |
Yahoo Messenger | =5.6.0.1351 | |
Yahoo Messenger | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0242 is considered to have a high severity due to its potential to allow attackers to execute arbitrary code.
To fix CVE-2005-0242, ensure that vulnerable versions of Yahoo Messenger are not used and consider updating to a patched version.
CVE-2005-0242 affects Yahoo Messenger versions 5.5, 5.6, and 6.0.0.1750.
CVE-2005-0242 is a code execution vulnerability that can be exploited via weak permissions on the Messenger program directory.
Yes, CVE-2005-0242 can be exploited remotely if the attacker can place a malicious ping.exe in the Yahoo Messenger directory.