Advertisement
Promo

Online business Toolkit

Users warned on Yahoo! Messenger attacks

Matthew Broersma ZDNet.co.uk

Published: 06 Jun 2002 15:06 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Yahoo! Messenger users have been alerted to a number of newly discovered holes in the instant messaging system, leaving their PCs open to malicious code and denial of service attacks.

CERT, a computer security response organisation, issued the warning on Wednesday, referring to two flaws discovered in late May. The flaws, a buffer overrun and a URL validation vulnerability, affect Yahoo! Messenger versions 5,0,0,1064 and earlier. Users are advised to upgrade to version 5,0,0,1065, released on Yahoo!'s site on 22 May, which patches the holes.

The first bug is a buffer overflow affecting Messenger's handler for Uniform Resource Indicators (URIs), software installed at the system level that is used by applications like Web browsers in processing Internet addresses. A URI sent in a Messenger message, embedded in a Web site or sent in an HTML email message can trigger the overflow, allowing hackers to execute code with the security privileges of the system's user, or shut down the system.

Yahoo! warned of this bug late last month.

The second bug affects Messenger's "addview" function, allowing an attacker to send malicious script or HTML in a message, which is then rendered in a Web browser.

CERT noted that a problem with Yahoo! servers after 22 May resulted in some users downloading the vulnerable Messenger version 5,0,0,1036 instead of the new version. The problem has since been fixed. Users can check which version they have by selecting the "About Yahoo! Messenger..." option from the Help menu.

Robert Mead, coordination centre manager for AusCERT, the organisation's Australian arm, said there is a danger that "people are pretty much executing (malicious) code on users' machines... Instant messaging is very widely used, at least in non-business environments."

However, businesses may also be at risk because many workers run the software on their office PCs. CERT noted that it had not yet detected hackers actively scanning for the vulnerabilities.

According Jupiter Media Metrix, 16 percent of workers with access to the Internet will be using Instant Messaging (IM) by the end of the year, with that figure expected to reach 46 percent by the year 2005.

ZDNet Australia's Rachel Lebihan contributed to this report.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
65 out of 127 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters