Yahoo! Messenger 5.0 allows remote attackers to spoof other users by modifying the username and using the spoofed username for social engineering or denial of service (flooding) attacks.
http://www.securityfocus.com/bid/4164
http://www.kb.cert.org/vuls/id/952875
http://www.iss.net/security_center/static/8267.php