Crucial Flaws Discovered in Yahoo! IM
08 Jun, 2007, 4:40 pm IST |
Priyanka Pradhan
|
|
Researchers at eEye Digital Security are reporting multiple vulnerabilities in Yahoo! Messenger, which can be used to remotely execute code. These vulnerabilities have reportedly come from Active X controls, installed in a computer. A Yahoo! spokesperson confirmed the company is looking into a buffer overflow issue in an Active X control. The company also said the vulnerabilities, which have obtained a rating of "high" by eEye Digital Security, were reported to Yahoo! on June 5 but are not known to have been exploited. Version 8.x of Yahoo! instant messaging (IM) client is at risk. In addition, officials from security research firm Secunia say, a boundary error within the Yahoo! Webcam Upload (ywcupl.dll) ActiveX control can be exploited to cause a stack-based buffer overflow by assigning an overly long string to the 'Server' property and then calling the 'Send()' or ' Receive ()' method. A study by Akonix Systems in San Diego (May 2007), a provider of instant messaging security and compliance products, uncovered 170 IM threats—an increase of 73 percent when compared to the number the company found between January and May of 2006. Read more here. |
Tags: Yahoo! Messenger
MAXX Adds Full Touch Mobile MT150 to its Scope
Exploring App Stores: Social Networking Apps for the iPad
Yahoo! Accused of Invading Users' Privacy
Video Calling Using Yahoo! Messenger on iPad 2
CeBIT 2007: Logitech Offers Webcams for Notebooks
Yahoo! Messenger Now Inside Mail
Leaked Images, Availability, Pricing,
Specs, Pre-order
5 free operating systems that aren't Linux
The war of operating systems started decades ago, and the first mainstream
It's a great time to be a family
Microsoft has unveiled its first ever global, multi-product advertising...
By Advertorial
In a sea of operating systems with Windows 7, the upcoming Windows 8 and...

Apple to announce 7-inch iPad?
Saravanabavagugan Vengadasundaram
Mon Feb 13, 11:17:29
Steve Jobs wins Grammy posthumously
Sandhya Patel
Mon Feb 13, 10:41:03
Microsoft Store in India hacked, usernames and passwords leaked
Rohan Kamble
Mon Feb 13, 10:34:39
More from Windows
More from this Author
LG Optimus Vu snapped alongside the Galaxy
Will the HTC Edge be renamed as Endeavor...
Apple to announce 7-inch iPad?
Apple rushing to finalize apps for iPad 3...



















Mixx
Facebook
Twitter
Digg
delicious
reddit
MySpace
StumbleUpon
LinkedIn

















































_011517074205_160x90.jpg)


















