McAfee Reports A Zero-Day Vulnerability in Yahoo Messenger
By Max Brenn
21:36, August 16th 2007
87 votes
Vote this story
McAfee Reports A Zero-Day Vulnerability in Yahoo Messenger

Beware with whom are you sharing the webcam on the Yahoo Messenger IM client. It might a friend, but it can be an intruder who wants to control your PC, by taking advantage of the latest vulnerability reported in Yahoo Messenger by McAfee.

The zero-day bug in Yahoo Messenger was reported for the first time by one of the McAfee’s Chinese security researchers.

The vulnerability was confirmed by McAfee on their AvertLabs blog. "It seems like a classic heap overflow which can be triggered when the victim accepts a webcam invite," Wei Wang, a security researcher at McAfee. "Note that this vulnerability is different from the recently patched one in June which exploited the Yahoo webcam ActiveX controls."

Wang is speaking about a vulnerability reported by the security firm eEye Digital Security, which was quickly fixed by Yahoo in the Version 8.1.0.401.

McAfee notified Yahoo about their finding, but until the company will issue a patch the users are being urged to protect themselves by not accepting webcam invites from untrusted sources.  

Also, "it's advisable to block outgoing traffic on TCP port 5100 until the vendor patches this vulnerability," Wang added. "To mitigate this, we're releasing our NIPS IntruShield signatures today to protect Yahoo Messenger users from this threat. We shall keep on monitoring this threat and update if we come across anything."

 



© 2007 - 2008 - eFluxMedia
dotclear

Other News in

A Better Place In The San Francisco Bay Area

A Better Place In The San Francisco Bay Area

The San Francisco Bay Area will feature in the near future a large charging stations network meant to support electric cars. Better Place, a company involved with developing this technology,...

BlackBerry Storm Arrives, But The Welcoming Committee is Undersized

BlackBerry Storm Arrives, But The Welcoming Committee is Undersized

Launch-time for BlackBerry Storm, but not very much to talk about when it comes to crowds of eager buyers lining up in front of the Verizon Wireless stores at 8 a.m. in the morning. Let’s be fair,...

Curiosity Gets Obama Account-Sniffing Verizon Employees Fired

Curiosity Gets Obama Account-Sniffing Verizon Employees Fired

Curiosity killed the cat, or in this case, got some employees fired… Verizon Wireless publicly announced that several of its employees have accessed President-elect Barack Obama’s personal cell phone...

Shocking: Teen Streams Webcam Suicide As Viewers Encourage Him

Shocking: Teen Streams Webcam Suicide As Viewers Encourage Him

Shocking news in the Web community, following the death of a Florida teenager who used a webcam to live stream his suicide video and share it with the world. The police arrived too late at the...

No More Free Communication Over The Phone For Barack Obama

No More Free Communication Over The Phone For Barack Obama

Verizon Wireless admitted late Thursday that several of its employees broke company rules by accessing and viewing President-elect Barack Obama's personal cell phone account. The company’s president...

dotclear
Latest videos in Technology
Google Mobile App for iPhone,...
Google SearchWiki
Previewing LA Auto Show
Yahoo CEO to resign
A 'social mobile' for the...

dotclear
Technology You are here: Technology
» Technology   » Gadgets   » Video Games   
E-mail To A Friend Print RSS Text size: Decrease font size Increase font size
dotclear
dotclear
dotclear
Most Popular in Technology
Judge Dismisses Psystar’s Countersuit Claims As UngroundedJudge Dismisses Psystar’s Countersuit Claims As Ungrounded

» read full story
dotclear

Interested In This Topic?

News Alert will keep you informed. Find out more.
dotclear
Photos Gallery
dotclear
Today's Latest News
Bronx Mowgli Benefits from Warm WelcomeBronx Mowgli Benefits from Warm Welcome

» read full story
dotclear