Yahoo Issues Messenger Security Fix
Yahoo has issued a patch for its instant messaging client, Yahoo Messenger.
The patch issued Wednesday addresses a buffer overflow vulnerability in an ActiveX control. Users who installed Yahoo Messenger before August 29, 2007 should install the update.
Microsoft’s ActiveX controls can interact with the full Windows operating system, unlike Java applets. This gives them a lot of power and also makes them potentially risky.
iDefense Labs identified the Yahoo Messenger vulnerability:
Exploitation allows attackers to execute arbitrary code with the privileges of the currently logged in user. Users would be required to have a vulnerable version of the target software installed and be lured to a malicious site.
Yahoo issued another security patch for Yahoo Messenger on August 21.
That patch addressed two security issues with the way the software’s Webcam functions work: susceptibility to a denial-of-service attack following a malicious Webcam invitation and a buffer overflow that could lead to the introduction of executable code by an attacker.
Comments
Leave a Reply
