Advertisement
Promo

Online business Toolkit

Users warned on Yahoo! Messenger attacks

Matthew Broersma ZDNet.co.uk

Published: 06 Jun 2002 15:06 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Yahoo! Messenger users have been alerted to a number of newly discovered holes in the instant messaging system, leaving their PCs open to malicious code and denial of service attacks.

CERT, a computer security response organisation, issued the warning on Wednesday, referring to two flaws discovered in late May. The flaws, a buffer overrun and a URL validation vulnerability, affect Yahoo! Messenger versions 5,0,0,1064 and earlier. Users are advised to upgrade to version 5,0,0,1065, released on Yahoo!'s site on 22 May, which patches the holes.

The first bug is a buffer overflow affecting Messenger's handler for Uniform Resource Indicators (URIs), software installed at the system level that is used by applications like Web browsers in processing Internet addresses. A URI sent in a Messenger message, embedded in a Web site or sent in an HTML email message can trigger the overflow, allowing hackers to execute code with the security privileges of the system's user, or shut down the system.

Yahoo! warned of this bug late last month.

The second bug affects Messenger's "addview" function, allowing an attacker to send malicious script or HTML in a message, which is then rendered in a Web browser.

CERT noted that a problem with Yahoo! servers after 22 May resulted in some users downloading the vulnerable Messenger version 5,0,0,1036 instead of the new version. The problem has since been fixed. Users can check which version they have by selecting the "About Yahoo! Messenger..." option from the Help menu.

Robert Mead, coordination centre manager for AusCERT, the organisation's Australian arm, said there is a danger that "people are pretty much executing (malicious) code on users' machines... Instant messaging is very widely used, at least in non-business environments."

However, businesses may also be at risk because many workers run the software on their office PCs. CERT noted that it had not yet detected hackers actively scanning for the vulnerabilities.

According Jupiter Media Metrix, 16 percent of workers with access to the Internet will be using Instant Messaging (IM) by the end of the year, with that figure expected to reach 46 percent by the year 2005.

ZDNet Australia's Rachel Lebihan contributed to this report.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
65 out of 130 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Sentry Posts Blog

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Symantec website breached

Security company Symantec has said that one of its websites was successfully breached. Romanian security researcher 'Unu' posted details of the breach in a blog post on Monday. Unu... More

Post a comment

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters