The Logfile feature in Yahoo! Messenger 5.x through 6.0 can be activated by a YMSGR: URL and writes all output to a single ypager.log file, even when there are multiple users, and does not properly warn later users that the feature has been enabled, which allows local users to obtain sensitive information from other users.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
http://marc.info/?l=bugtraq&m=111643475210982&w=2 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2005-05-19T04:00:00
Updated: 2024-08-07T21:59:23.523Z
Reserved: 2005-05-19T00:00:00
Link: CVE-2005-1671
Vulnrichment
No data.
NVD
Status : Modified
Published: 2005-05-19T04:00:00.000
Modified: 2024-11-20T23:57:51.960
Link: CVE-2005-1671
Redhat
No data.