Advertisement
Promo

Office applications Toolkit

Yahoo answers IM security flaw

Matt Hines CNET News

Published: 08 Dec 2003 10:40 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Yahoo has issued an update to its instant-messaging software, in order to address a security flaw found in the application.

The company said the security issue was related to a buffer overflow, which is a common security vulnerability in computer programs written in C and C++ that allows more information to be added to a chunk of memory than it was designed to hold.

Typical problems involved in an instant-messaging-related buffer overflow might include an involuntarily log-out of an IM session, a crash of browsing software applications, and a possible introduction of executable code. The last of the potential problems would likely cause the most damage, as the code might allow a malicious programmer to take control of a user's machine, delete files and otherwise wreak havoc with a victim's computer system.

According to Yahoo, only a small percentage of the company's IM software users might be vulnerable as a result of the flaw. Yahoo said customers who changed their Explorer security settings from "medium" to "low" could be affected. The company said that even in that case, an attacker would have to lure a user of Yahoo IM to view malicious HTML (Hypertext Markup Language) code. Most often this would entail clicking a link sent through IM that leads back to a Web page hosting the code. Before changing an IE security setting to low, individuals are warned by the browser that the setting is considered "highly unsafe." Yahoo said it has not yet heard of any successful attacks based on the buffer flaw.

Yahoo, which issued the new IM software on Thursday, reported that it first learned of the vulnerability via a warning posted to a security message board Tuesday night. The company said it immediately began working to validate the flaw and address the issue. Yahoo recommends updating its IM software on a regular basis to ensure customers are protected against similar flaws.

A nearly identical flaw was addressed in an earlier security patch distributed by Yahoo earlier this year.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
38 out of 70 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010

Discussions

ator1940 ator1940

Microsoft Loses Patent Case Appeal

Friday 25 December 2009, 9:35 PM

6 comments
J.A. Watson J.A. Watson

Google it

Friday 25 December 2009, 1:40 PM

3 comments
J.A. Watson J.A. Watson

Google it

Friday 25 December 2009, 1:38 PM

3 comments
Shibley R Shibley R

Question!

Friday 25 December 2009, 11:09 AM

3 comments

Vista Upgrade Blog

How to Upgrade From Windows Vista to W...

Did you get the news? Microsoft has unzipped its kitty and kept its latest, supposedly the best, offering on display. This is the brand new version of Microsoft operating system, named... More

Post a comment

Tinsel on the TARDIS

There were shepherds on the hill, and the Doctor popped his head out of the TARDIS and said "you might want to see this" and they were astounded. WHY do we pay for a TV license?... More

Post a comment

Can I have fries with that? (Consumer...

Licence policies of Tech company's have been for a long time both complicated and 'Dick Turpin-esque', people just click 'I agree' without reading the Agreement. I do the same, but... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters