You are here: silicon.com > Networks > WebWatch

WebWatch

Yahoo issues Messenger fix

A flaw in Yahoo IM could allow a user's computer to be taken over, says the company as it releases a patch

Tags: yahoo, flaw, instant messenger, patch

By Evan Hansen

Published: 2 June 2003 11:35 GMT

Yahoo on Friday issued security patches for its Yahoo Instant Messenger and Yahoo Chat clients in an effort to fix a buffer overflow vulnerability discovered in the software.

When users of the software log on to the IM network or enter a chat room, Yahoo is prompting them to install the patches. In addition, the company posted the patches on its Web site.

A buffer overflow is a common security vulnerability in computer programs written in C and C++ that allows more information to be added to a chunk of memory than it was designed to hold.

Buffer overflow attacks in Yahoo IM and Yahoo Chat could lead to a number of problems, according to a Yahoo representative. For example, people could be involuntarily logged out of an application. More seriously, it could allow the introduction of executable code, allowing a malicious programmer to take control of a user's machine, delete files and otherwise wreak havoc with a victim's computer system.

Such an attack could only happen if a victim were persuaded to view malicious HTML code, for example, by clicking on a link sent through IM that leads back to a Web page hosting the code. Yahoo said it was not aware of any IM or chat users compromised in this way.

A company representative said Yahoo was informed of the vulnerability by a member of the security community. Yahoo on Friday forwarded details of the vulnerabilities and their fixes to the Bugtraq security mailing list and Carnegie Mellon's CERT (Computer Emergency Response Team) security coordination centre.

Evan Hansen writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure
Read and write about internet access at the airports of the world at atlarge.com. Rate airports, and see what others have to say...

Peter Cochrane Peter Cochrane's Blog: How the telcos could save themselves Doomed network operators could thrive with a bit of innovation

Peter Cochrane Peter Cochrane's Blog: Facebook saves teen from prison Another unexpected impact of social networking


  • Jobs
SEO Specialist/Account Manager - Agency LDN

For a confidential chat and more information about this outstanding opportunity please send your CV to kbeswick @ energizerecruitment.co.uk - I ...

Vulnerability / Penetration tester (CEH) -

An immediate opening has arisen for a penetration / Vulnerability tester who also has a broad general Info sec background. The primary focus of the ...

Information Security Analyst (Attack Monitoring/Data Leakage/CISSP/CEH

You must have previous experience in a dedicated vulnerability management function where you have been responsible for all potential attacks on a ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: