The YMSGR URL handler in Yahoo! Messenger 5.x through 6.0 allows remote attackers to cause a denial of service (disconnect) via a room login or a room join request packet with a third : (colon) and an & (ampersand), which causes Messenger to send a corrupted packet to the server, which triggers a disconnect from the server.
| Software | From | Fixed in |
|---|---|---|
| yahoo / messenger | 5.6 | 5.6.x |
| yahoo / messenger | 5.5 | 5.5.x |
| yahoo / messenger | 6.0 | 6.0.x |