Security Advisory
CVE-2002-2361
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
The installer in Yahoo! Messenger 4.0, 5.0 and 5.5 does not verify package signatures which could allow remote attackers to install trojan programs via DNS spoofing.