NEWS The latest version of Yahoo's instant messenger software (YIM) contains a series of holes which could allow a hacker to take over a user's PC. The vulnerabilities in the software, which is used by up to 60 million people, allow the unauthorised execution of programs on a YIM user's machine via buffer overflows or injections of Java or Visual Basic script in the instant messenger content tabs. Security specialist Phuong Nguyen, of security firm Vice Consulting, is quoted as saying: "The net impact is to allow a relatively simple opportunity to hijack users' YIM client outright, and use it to attack or intrude into YIM users' supposedly private information systems." A malicious hacker could get hold of a user's ID and password and send it to an email address or internet URL. Malicious code could be buried in HTML pages or emails with text or images which encourage YIM users to click on them. Yahoo has already released a patch (http://messenger.yahoo.com ), but this will temporarily restrict the functionality of the software until the company secures the full version.
Yahoo's IM software a hacker's dream
Get your patch here...
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
Deliver easy email search, storage and retrieval systems
Are you storing up trouble? There is a better way to manage corporate email storage, especially to: - Avoid...
-
Systems engineering: Best practice for development success
Systems engineering isn't just a technical activity in the product lifecycle—it determines the commercial viability of...
-
Securing the rise of the mobile apps market: Code signing and mobile application development
The emergence of mobile applications has fundamentally changed the way that millions of people around the world, play...
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
Project Manager
Black Rock Studio [A division of Disney Interactive Media Group] is currently recruiting for a Project Manager to...
-
1st line Support- Croydon
My client- A large consultancy based in Croydon are looking for a 1st/2nd line helpdesk support candidate on an...
-
IT Security Specialist , Big Learning + Move into Pre-Sales
IT Security Specialist , Big Learning + Move into Pre-SalesSC Cleared, UK National - Intensive training offered on...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters




