Intelligence - Baseline
Home arrow Intelligence arrow Yahoo Patches IM Vulnerability



IBM Preps Carbon Transistors for Post-Silicon Era
IT Lessons from Toyota`s Fiasco
NIST Shrinks Antennas 50-fold with Metamaterials









Renew Your Subscription

  Intelligence


Yahoo Patches IM Vulnerability
By Brian Prince


Rate This Article:
Add This Article To:
A buffer overflow problem is patched by the company.

Yahoo has patched a buffer overflow vulnerability in its instant-messaging tool that would have enabled attackers to potentially execute code on a compromised machine.

The flaw exists in an ActiveX control that is part of the Yahoo Messenger audio conference control. If exploited, a buffer overflow could cause a user to be involuntarily logged out of a chat or instant messaging session, the crash of an application such as Internet Explorer or the execution of code.

Resource Library:
Read more here about Yahoo readying its new messenger.

According to the company, an attacker would have to trick a user into viewing malicious HTML code in order for the attack to be successful.

Andrew Storms, director of security operations for San Francisco-based nCircle, said addressing the vulnerability could pose a problem in large corporate environments where Yahoo Messenger is widely used.

"Yahoo IM is heavily used in the corporate environment even if security policy doesn't officially permit it," he said. "[This vulnerability] leaves administrators with the choices to upgrade or set the kill-bit on the affected ActiveX control. Unfortunately, many corporations are unable to centrally manage upgrades [to] Windows Messenger, making this fix extremely time-intensive for IT teams. Many companies will be performing ad-hoc mitigation to get this cleaned up."

Yahoo advises anyone who has installed Yahoo Messenger before March 13 to install the update.

Check out eWEEK.com's Security Center for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK's Security Watch blog.



Discuss Yahoo Patches IM Vulnerability
 
>>> Be the FIRST to comment on this article!
 

 
 
>>> More Intelligence Articles          >>> More By Brian Prince
 


Sponsored Links
  • Servers that cut energy costs by 95%? Cool.
  • Come see the Benefits of Desktop Virtualization on 3/18/10.
  • Simplicity is Power. Start simplifying with Citrix
  • Register for WES 2010 by March 26 and save $200.
  • FREE Sophos Encryption Tool: Encrypt, compress and share files easily.
  • CDW Healthcare offers the IT solutions you need.
  • One number. One voicemail. Sprint Mobile Integration.

     
  •  
    FEATURED SPONSORED MESSAGE

      Microsoft Windows Server 2008 R2

      Building on the award-winning foundation of Windows Server 2008, R2 enables IT professionals to increase the reliability and flexibility of their server infrastructures.

      Access a trove of Microsoft resources, analyst white papers, and multimedia presentations on Windows Server 2008 R2.

      Click Here

       Brought to You By


    FEATURED SPONSORED MESSAGE

     

    LATEST STORIES


     

     


    rss graphic
           Baseline Newsletters