Yahoo! Messenger File Extension Spoofing Vulnerability

Attackers may exploit this issue using Yahoo! Messenger and a malicious executable file.

Sample filenames and extensions have been provided:

example: Annakournikova and her friends.jpg~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@.exe Trojan.txt~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@~@.exe Info.txt~@~@~@~@~@~@~@~@~@~@~@~@~@~@.exe


 

Privacy Statement
Copyright 2010, SecurityFocus