CNCVE编号:CNCVE-20020027 CVE编号: 安全级别:中 漏洞中文描述: Yahoo! Messenger是Yahoo!即时信息服务的主客户端。Yahoo! Messenger实现上存在漏洞,在某些情况下攻击者可能得到用户的认证信息。Yahoo! Messenger version 5在用户进行认证的时候并不加密数据,如果第三方攻击者能够对用户客户端和服务器之间的通信进行窃听,那么攻击者可以容易地得到用户的认证信息。 漏洞英文描述: Yahoo! Messenger is the main client for Yahoo's instant messaging service. It has been reported that Yahoo! Messenger version 4 does not encrypt the data transferred when a user is authenticating. If a malicious third party could eavesdrop on network traffic between the messenger client and the Yahoo! Server, this could potentially disclose, in plain text, the authentication information of a user. 漏洞参考: http://archives.neohapsis.com/archives/bugtraq/2002-02/0273.html http://archives.neohapsis.com/archives/bugtraq/2002-02/0281.html 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:设计错误