CVE-2005-1671
Last modified
CVE-2005-1671 is a vulnerability of currently unknown severity. The Logfile feature in Yahoo! Messenger 5.x through 6.0 can be activated by a YMSGR: URL and writes all output to a single ypager.log file, even when there are multiple users, and does not properly warn later users that the feature has been enabled, which allows local users to obtain sensitive information from other users.. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
The Logfile feature in Yahoo! Messenger 5.x through 6.0 can be activated by a YMSGR: URL and writes all output to a single ypager.log file, even when there are multiple users, and does not properly warn later users that the feature has been enabled, which allows local users to obtain sensitive information from other users.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Yahoo | Messenger | 5.5 |
| Yahoo | Messenger | 5.6 |
| Yahoo | Messenger | 5.6.0.1351 |
| Yahoo | Messenger | 6.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-1671?
How severe is CVE-2005-1671?
How do I fix CVE-2005-1671?
Are you affected by CVE-2005-1671?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
