ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Yahoo fixes Messenger transfer flaw

Munir Kotadia ZDNet.co.uk

Published: 12 Jan 2004 12:45 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A serious security bug in Yahoo's Instant Messenger, which could cause a buffer-overflow error and leave users' machines open to malicious code, was finally repaired on Thursday.

A buffer overflow occurs when an application receives a string of data that is too long for it to handle. This leaves the sender of that data string in a position to load the buffer with another value, allowing malicious code to be executed instead of the original program. In this case, the error affected versions 5.6.0.1351 and earlier of Yahoo's IM client software, and was triggered when a user downloaded a file with a name that was a specific number of characters in length. A server-side fix means that users will not have to upgrade their software.

Tri Huynh, a security consultant based in Massachusetts, who claims to have discovered the problem two months ago, told ZDNet UK that the bug posed serious problems because of the ease with which PCs could be infected. "This is highly critical. When you get sent a file and you save it, you don't even need to open the file for the overflow to happen," he said.

A Yahoo spokeswoman told ZDNet UK that the company had fixed the bug in their server software on Thursday. "Upon learning of this issue, we immediately began working towards a resolution and implemented a server-side fix early on Thursday morning, eliminating the need for users to download a patch or a new version of Yahoo Messenger," she said. "We are not aware of any active exploits that have affected our users."

This is the second buffer-overflow bug that has been reported in Yahoo's popular instant messenger program in less than a month.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
54 out of 108 people found this useful



Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Test Analyst - kNOWLEDGE of Asset Classes / FIX / OMS / Trading

One of the leading global Software houses based in the city is currently looking to add a business Test Analyst into their testing team. To be ...

IT Help Desk Analyst

To co-ordinate the communication from 2nd and 3rd line support to users managing expectations for likely fix times and call status. Excellent ...

Equities & FIX Application Support Specialist - Contract

Working knowledge of the FIX protocol (versions 4.0; 4.2 and 4.4). My Client has a requirement for an Equity and Exchange Connectivity Support ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment