McAfee Reports A Zero-Day Vulnerability in Yahoo Messenger
By Max Brenn
21:36, August 16th 2007
59 votes
Vote this story
McAfee Reports A Zero-Day Vulnerability in Yahoo Messenger

Beware with whom are you sharing the webcam on the Yahoo Messenger IM client. It might a friend, but it can be an intruder who wants to control your PC, by taking advantage of the latest vulnerability reported in Yahoo Messenger by McAfee.

The zero-day bug in Yahoo Messenger was reported for the first time by one of the McAfee’s Chinese security researchers.

The vulnerability was confirmed by McAfee on their AvertLabs blog. "It seems like a classic heap overflow which can be triggered when the victim accepts a webcam invite," Wei Wang, a security researcher at McAfee. "Note that this vulnerability is different from the recently patched one in June which exploited the Yahoo webcam ActiveX controls."

Wang is speaking about a vulnerability reported by the security firm eEye Digital Security, which was quickly fixed by Yahoo in the Version 8.1.0.401.

McAfee notified Yahoo about their finding, but until the company will issue a patch the users are being urged to protect themselves by not accepting webcam invites from untrusted sources.  

Also, "it's advisable to block outgoing traffic on TCP port 5100 until the vendor patches this vulnerability," Wang added. "To mitigate this, we're releasing our NIPS IntruShield signatures today to protect Yahoo Messenger users from this threat. We shall keep on monitoring this threat and update if we come across anything."

 



© 2007 - 2008 - eFluxMedia
dotclear

Other News in

Microsoft Reveals Online Service Bundles

Microsoft Reveals Online Service Bundles

At its annual Worldwide Partner Conference that took place in Huston, Microsoft announced two online service bundles that are targeted to two opposite types of workers: the ones that hardly use the...

Viacom Tramples Privacy of YouTube Users with Court Help

Viacom Tramples Privacy of YouTube Users with Court Help

The ruling which demands Google to hand over the YouTube access logs, which are to show the actual extent of copyright infringement going on the popular site, has sparked widespread outrage from...

Microsoft Discovers IE Vulnerability

Microsoft Discovers IE Vulnerability

Microsoft warns its users about a recently discovered attack on one of its browser components. The reports received by the company, refer to a flaw in an ActiveX control for Snapshot Viewer, active...

Apple To Launch Its MobileMe On Wednesday, July 9th

Apple To Launch Its MobileMe On Wednesday, July 9th

Apple has officially unveiled the launch date of its MobileMe service, announced last month at WWDC 2008. The users of www.mac.com were notified that the site will be taken offline on Wednesday, July...

Unexpected New “Words” Make Their Way Into The Merriam-Webster

Unexpected New “Words” Make Their Way Into The Merriam-Webster

Did you ever think you’ll find words like “fanboy,” “pretexting” or “pescatarian” in the dictionary any time soon? Well, for you, and even for those who’ve never heard of them but probably will...

dotclear
Latest videos in Technology
YouTube ruling spurs privacy...
Google ordered: hand over...
Microsoft after Gates
Mobile precautions urged
What Yahoo turned down

dotclear
Technology You are here: Technology
» Technology   » Gadgets   » Video Games   
E-mail To A Friend Print RSS Text size: Decrease font size Increase font size
dotclear
dotclear
dotclear
Most Popular in Technology
Update: Viacom-YouTube Ruling Triggers Far-Reaching Privacy ConcernsUpdate: Viacom-YouTube Ruling Triggers Far-Reaching Privacy Concerns

» read full story
dotclear

Interested In This Topic?

News Alert will keep you informed. Find out more.
dotclear
Photos Gallery
dotclear
Today's Latest News
FDA Wants Black Box on Antibiotics, Epilepsy DrugsFDA Wants Black Box on Antibiotics, Epilepsy Drugs

» read full story
dotclear