NEWS Yahoo on Friday issued security patches for its Yahoo Instant Messenger and Yahoo Chat clients in an effort to fix a buffer overflow vulnerability discovered in the software. When users of the software log on to the IM network or enter a chat room, Yahoo is prompting them to install the patches. In addition, the company posted the patches on its Web site. A buffer overflow is a common security vulnerability in computer programs written in C and C++ that allows more information to be added to a chunk of memory than it was designed to hold. Buffer overflow attacks in Yahoo IM and Yahoo Chat could lead to a number of problems, according to a Yahoo representative. For example, people could be involuntarily logged out of an application. More seriously, it could allow the introduction of executable code, allowing a malicious programmer to take control of a user's machine, delete files and otherwise wreak havoc with a victim's computer system. Such an attack could only happen if a victim were persuaded to view malicious HTML code, for example, by clicking on a link sent through IM that leads back to a Web page hosting the code. Yahoo said it was not aware of any IM or chat users compromised in this way. A company representative said Yahoo was informed of the vulnerability by a member of the security community. Yahoo on Friday forwarded details of the vulnerabilities and their fixes to the Bugtraq security mailing list and Carnegie Mellon's CERT (Computer Emergency Response Team) security coordination centre. Evan Hansen writes for CNET News.com
Yahoo issues Messenger fix
A flaw in Yahoo IM could allow a user's computer to be taken over, says the company as it releases a patch
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Latest Networks stories
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
WAN Optimization for Today and Tomorrow.
It was only a few years ago when the idea of mobile computing seemed like a distant reality. Many could see it coming,...
-
Six iPad tests for multimedia-grade Wi-Fi
Along with most companies, the University of Ottawa has seen a massive increase in the numbers of highly mobile...
-
Solution Brief: Top 5 Reasons to Choose Blue Coat WAN Optimization
There's a pretty good chance your wide area network (WAN) looks like a mess right now. The rapid adoption of new...
Popular Networks stories
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
Architect Java, J2EE, Oracle, Spring London £55-65K
Java, J2EE, Oracle, PL/SQL, SQL, Spring, Struts, Maven, Swing Java, J2EE, Oracle My client a premiere...
-
Business Analyst ( ISEB, CBAP, BA, Analyst)
Business Analyst ( ISEB, CBAP, BA, Analyst) £31,000-£42,000 + excellent benefits We take the best Business...
-
Embedded C / MISRA C / DO178B - SouthCoast
I have just received instruction from a key client of mine for an Electronic Design Engineer in the Gloucestershire...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters





