On mySimon: Hunter Wellies Rain Boots For Men
BNET Business Network:
BNET
TechRepublic
ZDNet

By Matt Hines
Posted on ZDNet News: Dec 5, 2003 7:59:00 PM

Yahoo issued an update to its instant-messaging software, in order to address a security flaw found in the application earlier this week.

The company said the security issue was related to a buffer overflow, a common security vulnerability in computer programs written in C and C++ that allows more information to be added to a chunk of memory than it was designed to hold.

Typical problems involved in an instant-messaging-related buffer overflow might include an involuntarily log-out of an IM session, a crash of browsing software applications, and a possible introduction of executable code. The last of the potential problems would likely cause the most damage, as the code might allow a malicious programmer to take control of a user's machine, delete files and otherwise wreak havoc with a victim's computer system.

According to Yahoo, only a small percentage of the company's IM software users might be vulnerable as a result of the flaw. Yahoo said customers who changed their Explorer security settings from "medium" to "low" could be affected. The company said that


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


even in that case, an attacker would have to lure a user of Yahoo IM to view malicious HTML (Hypertext Markup Language) code. Most often this would entail clicking a link sent through IM that leads back to a Web page hosting the code. Before changing an IE security setting to low, individuals are warned by the browser that the setting is considered "highly unsafe." Yahoo said it has not yet heard of any successful attacks based on the buffer flaw.

Yahoo, which issued the new IM software Thursday, reported that it first learned of the vulnerability via a warning posted to a security message board Tuesday night. The company said it immediately began working to validate the flaw and address the issue. Yahoo recommends updating its IM software on a regular basis to ensure customers are protected against similar flaws.

A nearly identical flaw was addressed in an earlier security patch distributed by Yahoo earlier this year.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 2 Talkback(s)
Why not fix the whole thing!
Hey Steve ! why not as them to rewrite the whole thing so Linux users have a comparable client to what windows does?... (Read the rest)
Posted by: nite_w0lf Posted on: 12/06/03 You are currently: a Guest | | Terms of Use
Fix Yahoo IM File Sharing On Linux Next  SteveProgrammer | 12/06/03
Why not fix the whole thing!  nite_w0lf | 12/06/03

What do you think?

advertisement
advertisement
Click Here

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here