The installer in Yahoo! Messenger 4.0, 5.0 and 5.5 does not verify package signatures which could allow remote attackers to install trojan programs via DNS spoofing.
| Software | From | Fixed in |
|---|---|---|
| yahoo / messenger | 5.5 | 5.5.x |
| yahoo / messenger | 5.0 | 5.0.x |
| yahoo / messenger | 4.0 | 4.0.x |