Search Perform an advanced search query SOFTPEDIA
 
SOFTPEDIA
Updated one minute ago
HomeSubmit a program for being reviewedAdvertise on our websiteGet help on surfing our websitesSend us your feedbackGet information about our XML/RSS backend and how to use itBrowse the news archiveVisit our discussion forumVizitati forumul in limba romana



KLIP
  1. HOME
  2. SCIENCE
  3. TECHNOLOGY
  4. WEBMASTER
  5. SECURITY
  6. MICROSOFT
  7. LINUX
  8. APPLE
  9. GAMES
  10. TELECOMS
  11. REVIEWS
  12. LIFE & STYLE
  13. EDITORIALS
  14. INTERVIEWS
  15. RSS
Welcome!
Hello, Guest

Login if you have a Softpedia.com account.

Otherwise, register for one.

SECURITY

Yahoo Messenger ActiveX Vulnerability

- Allows for remote code execution

By: Marius Oiaga, Technology News Editor

All Yahoo Messenger users that have installed the IM client prior to November 2, 2006 are vulnerable to attacks that exploit a buffer overflow in an ActiveX control of the product. According
to data released by Secunia, Yahoo! Messenger 5.x, Yahoo! Messenger 6.x, Yahoo! Messenger 7.x and Yahoo! Messenger 8.x are all vulnerable to attacks.

"Some impacts of a buffer overflow might include being involuntarily logged out of a Chat and/or Messenger session, the crash of an application such as Internet Explorer, and in some instances, the introduction of executable code. For this specific issue, these impacts could only be possible if an attacker is successful in prompting someone to view malicious HTML code, most likely executed by getting a person to visit their web page. To our knowledge, there have been no known executable code exploits related to this issue," revealed Yahoo.

Although the Sunnyvale-based Internet giant denies the existence of exploits, Secunia has rated the vulnerability as Highly Critical due to the fact that a successful exploit could permit remote code execution. "The vulnerability is caused due to an unspecified error in an ActiveX control and can be exploited to cause a buffer overflow. No further information is currently available. The vulnerability is reported in versions obtained prior to Nov 2, 2006," stated Secunia.

In this context, Yahoo is supplying an update to resolve the ActiveX buffer overflow vulnerability. All you have to do is to install the latest version of the instant messenger client.

MORE RELATED ARTICLES: Microsoft Increases MSN Hotmail Storage Space Upgrade to IE7 Optimized for Google MSN/Live Search Market Share Sinks MSN/Windows Live Search Drops 8% in Search Share All Eyes on Online Video Windows Live Projects Indefinitely Postponed MSN Is Unsafe MSN Premium Unveils Version 9.5 Get Cookin' with MSN IE7 Speaks Chinese and Hebrew
 
Comments | Link here | Subscribe
Print | Send to friend
Today's News | Yesterday's News

Search:

15th December 2006, 13:54 GMT | Copyright (c) 2006 Softpedia | Contact:
Read by 1,958 user(s) | Rating: | 10 vote(s) so far | Cast your vote:
Yahoo Messenger ActiveX Vulnerability - USER OPINIONS




We are sorry, there are no opinions available for this article.






SHARE YOUR OPINION ABOUT Yahoo Messenger ActiveX Vulnerability

Since you are not logged on, your comments will have to be approved before being displayed.
Click here to login, or register.
Your Name:
Your Email:
Type in the result:
Your Opinion:
 


DO YOU WANT TO CONTACT US?  

If you have some comments or you want to send us some information you can send us an email directly to .
You can use the form below for the same purpose.
Your full name: (at least 3 characters)
Your email address: (at least 5 characters)
Message subject: (at least 5 characters)
Message text:
(at least 10 characters)
Type in the result:
 
 



© 2001 - 2008 Softpedia. All rights reserved.
Softpedia™ and Softpedia™ logo are registered trademarks of SoftNews NET SRL.
Copyright Information | Privacy Policy | Terms of Use | Contact Softpedia | Update your software | Archive