Latest Comments
"My AVG WILL NOT UPDATE"
by James Downs | Dec 2, 2008 5:58 AM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM

Yahoo patches Messenger ActiveX control flaws

  • Email a Friend
  • Print Page
Yahoo patches Messenger ActiveX control flaws
By Frank Washkuch
Jun 12, 2007 9:52 AM | 1 Comment
Tags: Yahoo | patches | Messenger | ActiveX | control | flaws
The Sunnyvale, Calif.-based web giant encouraged Messenger users to download version 8.1.0.410 from its website.

"The Yahoo Messenger team recently learned of a buffer overflow security issue in ActiveX control. Upon learning of this issue, we began working toward a resolution and implemented a fix to Yahoo Messenger’s software download," read a statement released today by Yahoo spokesman Terrell Karlsten. "We are encouraging all Yahoo Messenger users to download the latest version available at messenger.yahoo.com."

Users will be prompted to download a new version of Messenger in the coming weeks, according to the statement.

According to an advisory released Thursday, Yahoo was made aware of the flaw by eEye Digital Security.

A hacker using the handle "Danny" released two zero-day ActiveX exploits for Yahoo Messenger’s Webcam application on the Full Disclosure mailing list on Thursday.

Secunia ranked the flaws as "highly critical" and FrSIRTassigned them a "high" risk ranking.

One flaw is a boundary error within the Yahoo Webcam Upload ActiveX control, which can be exploited to cause a stack-based buffer overflow, according to a Security advisory updated today.

The other vulnerability exists within the Yahoo Webcam Viewer ActiveX control and can also be exploited for a stack-based buffer overflow attack, according to Secunia.

Don Montgomery, vice president of marketing at Akonix, told SCMagazine.com that better email security solutions and the convergence of networks are two reasons hackers are turning their attention to IM

"They are turning to this pathway because it’s still open to them. Obviously, email is still a big spam target, but not as big of a target for viruses," he said.

 
Ads by Google
Thoughts on this article? Add a comment below.
Comments: 1
Good
SC Magazine - comments icon Posted by Francis AyiteyOct 6, 2008 10:48 AM
Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Patch Management Whitepapers