
Whatever happened to the idea of video calls on the go when 3G first arrived? »more
Yahoo patch squashes messenger bug
11-06-2007
by The Register
Yahoo bug crushers have plugged a serious hole in Yahoo Messenger that made it possible for bad guys to remotely take control of a user's machine.
The update became available less than 24 hours after an anonymous hacker posted proof-of-concept code that demonstrated how the vulnerability could be exploited.
The vulnerability stems from a buffer overflow flaw in the messenger's ActiveX control. Attackers could use it to remotely execute malicious code, or for other, less serious things, such forcing a user to log out of a chat or instant messaging session or crash Internet Explorer or another application. To carry out the attack, a miscreant must first prompt the victim to visit a booby-trapped website that contains specially crafted html code.
Ironically, Yahoo's own discussion of the flaw may have led to the exploit code, according to Marc Maiffret, a researcher at eEye Digital Security, the security firm that discovered the security hole. An advisory eEye posted on Wednesday warned only that "multiple flaws exist within Yahoo Messenger which allow for remote execution of arbitrary code with minimal user interaction", eEye refused to say more publicly, out of concern the additional details would enable someone to target the holes.
That didn't stop a Yahoo spokeswoman from disclosing in a story by Information Week that the security issue was connected to a buffer overflow in Yahoo Messenger's ActiveX control. She revealed that it was part of the code the program uses to upload and view web cam images.
Shortly thereafter, a person going by the name of Danny posted exploit code here and in the same dispatch included a link to the Information Week article.
A Yahoo spokeswoman didn't have an immediate comment on the company's vulnerability disclosure practices.
Maiffret, who holds up Microsoft as a model for responsible vulnerability handling, has no doubt Yahoo tipped its hands to hackers by giving so many details before a patch was available for download. He says companies responding to security problems should learn from the mistake.
"A lot of these non-Microsoft companies, if you will, are still behind in vulnerability response practices," he says. "This just goes to show it. There's no reason at all for a vendor to list the components."
The Register and its contents are copyright 2007 Situation Publishing. Reprinted with permission.
• Microsoft grapples with mystery DRM cracker
• Yahoo to distribute Symantec security product
• JavaScript worm targets Yahoo
• IM worm installs rogue browser
Yahoo » Create Alert
Security » Create Alert
E-security » Create Alert
» Define your own keyword alert
• Data protection: burden of responsibility?
• ESA puts out the call for astronauts
• For the record 12 May
• Full steam ahead for Apple's iPhone
• Oracle sharpens axe for BEA layoffs
• Original Solutions bought by Perot
• Rattleblog: Tales from the blogosphere
Here's an interesting fact. In the first three months of 2008 Dell's sales rose 14pc in the UK according to Gartner. That's probably due to the recent deals » Read more

Sign up free, click here
To change your ENN Newsletter and alerts preferences here
In the wake of the recent Bank of Ireland laptop thefts, it's a good time to ask what should be done to safeguard our data.
» Read more
This month's Rattleblog talks about Yahoo being a runaway bride and changing its ways to become a better company, even more hype about the iPhone and why advertising is now the revenue model for most tech start-ups. »more
Business & IT Summit
9am, The Royal College of Physicians, Kildare Street
» View more events
» Post your event on ENN




