NEW Zero Day Exploit Hits Yahoo MessengerBest Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
GFI LANguard Network Security Scanner - Dld 30-day trial! del.icio.us  digg  Furl  NewsVine  Spurl  Blinklist  Ma.gnolia  Reddit  Tailrank  YahooMyWeb 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
Downloads
RSS / Atom Feeds
Windows Security : NEW Zero Day Exploit Hits Yahoo Messenger
Posted by Max on 2007/8/16 13:21:53 (674 reads)
Windows Security

A post on a Chinese-language security forum claims that there is a zero-day vulnerability in Yahoo Messenger. Researchers at Avert Labs have found that this flaw may allow for user-assisted remote-code execution attacks. No code exploiting this flaw has been published yet.

The vulnerability, apparently a heap-overflow bug, can be exploited by duping a user into accepting a malicious webcam invitation, said Wei Wang, a Beijing-based researcher at McAfee's Avert Labs.

Yahoo Inc.'s security team has been told of the bug and its exploit, Wei added.

This new zero-day vulnerability is Messenger's second in the past 30 days, and its third since early June. Last month, a researcher posted news of a buffer overflow in the instant messaging client triggered by a malformed address book entry. The bug has not been patched, even though a Yahoo spokeswoman said July 17 that one would be issued "shortly."

In June, eEye Digital Security fingered Messenger for a critical ActiveX vulnerability in the software's webcam feature; Yahoo patched that bug June 7.

"[Today's] vulnerability is different from the recently patched one in June," Wei said. Until the IM client is patched, McAfee recommended that users ignore unexpected webcam invites and block outbound traffic on TCP Port 5100.

As in July, a Yahoo spokeswoman said the company was "working toward a resolution and expect[s] to have a fix shortly."




Other articles
2008/8/21 15:52:01 - BitRoll and Torrent101 Used to Distribute the Lop Adware
2008/8/20 15:06:33 - FRAUDFacts Helps You Fight Identity Theft and Fraud for Life
2008/8/13 16:42:03 - 10 Million Zombies Are Spreading Spam and Malware Every Day
2008/8/11 9:03:35 - Nearly $8.5 Billion Lost by US Consumers because of Online Threats
2008/8/8 6:35:36 - EDS' Eight Tips for Consumers to Protect Themselves from Identity Theft

The comments are owned by the poster. We aren't responsible for their content.