
Whatever happened to the idea of video calls on the go when 3G first arrived? »more
Yahoo battered by second ActiveX vulnerability
03-09-2007
by The Register
Yahoo users are urged to upgrade their instant messaging software following the discovery of a brace of security vulnerabilities -- the second set of serious security flaws involving Yahoo Messenger in as many weeks.
The latest security bugs both stem from stack-based buffer overflow flaws in the YVerInfo.dll ActiveX control. Successful exploitation, which is far from straightforward, creates a means for hackers to inject hostile code onto systems running vulnerable versions of Yahoo Messenger.
In order to exploit the bugs, hackers would need to establish a malicious web page in the yahoo.com domain, which might be done by methods such as a cross-site scripting vulnerability or by manipulating DNS resolution, security notification firm Secunia reports.
The vulnerabilities affect versions of Yahoo Messenger 8.x prior to version 8.1.0.419, released late last week. Users are urged to upgrade.
More background can be found in security advisories from Yahoo (here) and iDefense (here), the firm that discovered the bug.
Last month security researchers identified an even more serious bug -- again involving a dodgy ActiveX control -- that meant users were exposed to attack providing they accepted a webcam invite from a hacker.
In order to exploit the bugs, hackers would need to establish a malicious web page in the yahoo.com domain, which might be done by methods such as a cross-site scripting vulnerability or by manipulating DNS resolution, security notification firm Secunia reports.
The Register and its contents are copyright 2007 Situation Publishing. Reprinted with permission.
Yahoo » Create Alert
Security » Create Alert
Activex » Create Alert
» Define your own keyword alert
• Data protection: burden of responsibility?
• ESA puts out the call for astronauts
• For the record 12 May
• Full steam ahead for Apple's iPhone
• Oracle sharpens axe for BEA layoffs
• Original Solutions bought by Perot
• Rattleblog: Tales from the blogosphere
Here's an interesting fact. In the first three months of 2008 Dell's sales rose 14pc in the UK according to Gartner. That's probably due to the recent deals » Read more

Sign up free, click here
To change your ENN Newsletter and alerts preferences here
In the wake of the recent Bank of Ireland laptop thefts, it's a good time to ask what should be done to safeguard our data.
» Read more
This month's Rattleblog talks about Yahoo being a runaway bride and changing its ways to become a better company, even more hype about the iPhone and why advertising is now the revenue model for most tech start-ups. »more
Business & IT Summit
9am, The Royal College of Physicians, Kildare Street
» View more events
» Post your event on ENN




