Advertisement
Promo

Security threats Toolkit

Yahoo mail flaws fixed

Published: 20 Aug 2004 09:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Yahoo fixed two flaws in its free mail system that could have allowed a malicious user to read a victim's browser cookies and change the appearance of some pages, Yahoo said on Thursday.

A representative of the company said the flaws were fixed last month by making changes on the company's Yahoo Mail servers.

"We were alerted of it at the end of May, early June," spokeswoman Mary Osako said. "There ended up being two variations of the issue: one which we could reproduce in a few days and the other which took a lot of effort to reproduce."

The vulnerabilities are of a type known as cross-site scripting flaws, which typically take advantage of scripting languages and misconfigured Web servers to launch attacks against a user's computer. The attacks typically redirect the user to another Web site, allow access to the user's cookies or, sometimes, allow the attacker to run code on the victim's computer.

Yahoo fixed the flaws in its server code. No patch is required by the Yahoo Mail users.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
73 out of 139 people found this useful


Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

South Korea plans to fingerprint visit...

The South Korean authorities could fingerprint and photograph foreign visitors from 2012, the Korea Times reported on Tuesday. Barring diplomats and government operatives, all visitors... More

Post a comment

Adobe Reader in the Enterprise

This week I had the pleasure of working with some of the Microsoft Premier Field Engineers (PFE's) in an effort to further understand some of the application compatibility issues that... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters