CVE-2005-1618: Medium severity Yahoo Messenger vulnerability
The YMSGR URL handler in Yahoo! Messenger 5.x through 6.0 allows remote attackers to cause a denial of service (disconnect) via a room login or a room join request packet with a third : (colon) and an & (ampersand), which causes Messenger to send a corrupted packet to the server, which triggers a disconnect from the server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-1618?
CVE-2005-1618 has a medium severity rating due to its potential for causing denial of service in affected versions of Yahoo Messenger.
How does CVE-2005-1618 exploit the system?
CVE-2005-1618 exploits the YMSGR URL handler by sending malformed room login or join requests that lead to a corrupt packet, causing disconnections.
What versions of Yahoo Messenger are affected by CVE-2005-1618?
CVE-2005-1618 affects Yahoo Messenger versions 5.5, 5.6, and 6.0.
How can I mitigate the risk of CVE-2005-1618?
To mitigate CVE-2005-1618, users should upgrade to a later version of Yahoo Messenger that is not affected by this vulnerability.
Is CVE-2005-1618 still a concern for current users?
CVE-2005-1618 is less of a concern for current users, as Yahoo Messenger has been discontinued and modern alternatives do not have this vulnerability.