Portal IT :: News, download, directory


Search: Thursday 4 December 2008









Add to Google Add to My Yahoo!


  Add to Favorites   Set Home Page





« december 2008
s m t w t f s
30 1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30 31 1 2 3
4 5 6 7 8 9 10







New Yahoo Messenger Flaw Unveiled
Published on Software  |  August 22, 2007, 13:58

A new Yahoo Messenger vulnerability has been discovered. However, a few common sense steps should be more than enough to keep users safe until a patch will be released. The flaw affect both Yahoo Messenger 8.0 and 8.1 (Windows versions).

McAfee was the first to get hold of the news and the results of its tests were posted on the company's Avert Labs blog:

“[...]we got a chance to dig a bit deeper into this and were able to reproduce the vulnerability on Yahoo! Messenger version 8.1.0.413 based on the information provided in the forum. It seems like a classic heap overflow which can be triggered when the victim accepts a webcam invite. [...] We’ve been able to reach Yahoo! security team and have informed them about this issue.”

The company advises users not to accept webcam invites from untrusted sources until a patch is released. Also, McAfee adds that would be a good move to block outgoing traffic on TCP port 5100 until the vendor patches this vulnerability

Yahoo's previous Messenger bug issue dates from June, when eEye Digital Security discovered two critical vulnerabilities in ywcupl.dll (version 2.0.1.4) and ywcvwr.dll (version 2.0.1.4), both of them Webcam ActiveX components, included by default in all releases of Yahoo! Messenger 8.x. The June exploit took advantage of buffer overflow issues within the Webcam ActiveX component.


Rate this       Low   High
Curent Rating: 3.1/5 by 15 users
 Print       Email      IM 




 
More Software News
 
Daily News Alert

 
Advertising
 
Top Rated Software News This Month