You are here: silicon.com > Networks > WebWatch

WebWatch

Yahoo issues Messenger fix

A flaw in Yahoo IM could allow a user's computer to be taken over, says the company as it releases a patch

Tags: flaw, instant messenger, patch, yahoo

By Evan Hansen

Published: 2 June 2003 11:35 BST

Yahoo on Friday issued security patches for its Yahoo Instant Messenger and Yahoo Chat clients in an effort to fix a buffer overflow vulnerability discovered in the software.

When users of the software log on to the IM network or enter a chat room, Yahoo is prompting them to install the patches. In addition, the company posted the patches on its Web site.

A buffer overflow is a common security vulnerability in computer programs written in C and C++ that allows more information to be added to a chunk of memory than it was designed to hold.

Buffer overflow attacks in Yahoo IM and Yahoo Chat could lead to a number of problems, according to a Yahoo representative. For example, people could be involuntarily logged out of an application. More seriously, it could allow the introduction of executable code, allowing a malicious programmer to take control of a user's machine, delete files and otherwise wreak havoc with a victim's computer system.

Such an attack could only happen if a victim were persuaded to view malicious HTML code, for example, by clicking on a link sent through IM that leads back to a Web page hosting the code. Yahoo said it was not aware of any IM or chat users compromised in this way.

A company representative said Yahoo was informed of the vulnerability by a member of the security community. Yahoo on Friday forwarded details of the vulnerabilities and their fixes to the Bugtraq security mailing list and Carnegie Mellon's CERT (Computer Emergency Response Team) security coordination centre.

Evan Hansen writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure
Read and write about internet access at the airports of the world at atlarge.com. Rate airports, and see what others have to say...

Rob Bamforth Seeking memorable mobile apps Quocirca's Straight Talking: Why are there so few?

Stewart Baines How much SEO is too much? Net Effect: Plus 10 tips on boosting your site's profile


  • Jobs
Systems Administrator - ITIL, Linux, Hosting - Relocaters welcome

You will need to understand how to install and configure a server; principles of security and post-install lock-down of servers; user accounts and ...

Junior Publisher Account Manager

Yahoo! ve continued to build innovative and imaginative experiences that are uniquely Yahoo! Today, across the globe, over 550 million people use ...

Fantastic Pharmaceutical Project Assistant Croydon

Quality Start will offer 200 to anyone who successfully recommends a candidate who is subsequently employed by our client.To apply for this one of ...

Agenda Setters 2008
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: