TECH.BLORGE.com
VISTA.BLORGE.com
MAC.BLORGE.com
GAMER.BLORGE.com

June 9, 2007 |

Yahoo patches critical bugs in messenger

By Ruben Francia





Yahoo Patches Critical Bugs In MessengerYahoo has released a critical security patch for its Messenger instant messaging client to address zero-day exploits that could compromise PCs remotely, with no or minimal interaction required by the user.

The patch comes after a hacker released two ActiveX exploits for Yahoo Messenger’s Webcam application on the Full Disclosure mailing list.

eEye Digital Security first reported the flaws to Yahoo earlier this week without disclosing specific details of the bug.

eEye gave the problem its highest risk rating.

“ActiveX remote code execution vulnerabilities have very high impacts since the source of the malicious payload can be any site on the Internet,” the security company said in its alert.

All existing versions of Messenger instant messaging client running on Windows are vulnerable to attack, according to eEye.

“The impact of this vulnerability is extensive because it could allow attackers to take complete control of a user’s system, and two public proof-of-concept exploits are available. This leaves many thousands of internet consumers at high risk,” said Andrew Storms, director of security operation for nCircle, a provider of enterprise-class vulnerability and risk management solutions.

Yahoo’s advisory on the problem states that anyone using a version of Messenger instant messaging client running on Windows obtained before Friday should download the update.

Related:

  • New security flaw found in Yahoo! Messenger
  • Yahoo launches Yahoo Web Messenger
  • Microsoft issues 20 Windows patches but none for Vista. Yet.
  • Yahoo outsourcing Messenger calls to startup Jajah
  • Microsoft misses internal deadline for Vista RTM




  • Sign up for the BLORGE daily email newsletter

    One Response to “Yahoo patches critical bugs in messenger”

    1. christine edwards:

      I have paid to play Boggle some time agao and now cannot get back to play it – Please sort this out and connect me back to this game. I cannot remember my password or sign it details

    Leave a Reply:

    Copyright © 2008 Engaging and compelling blogs that entertain and inform