HomeBusinessHardwareSoftwareTelecomsPersonal Technology

 


















ZDNet UK > News > Story




Previous Story: Nintendo aims high with GameCube Next Story: Teleworking growth surges ahead in the UK
Users warned on Yahoo! Messenger attacks
15:06 Thursday 6th June 2002
Matthew Broersma 

New security holes could give attackers control of users' PCs - and businesses are also at risk

Yahoo! Messenger users have been alerted to a number of newly discovered holes in the instant messaging system, leaving their PCs open to malicious code and denial of service attacks.

CERT, a computer security response organisation, issued the warning on Wednesday, referring to two flaws discovered in late May. The flaws, a buffer overrun and a URL validation vulnerability, affect Yahoo! Messenger versions 5,0,0,1064 and earlier. Users are advised to upgrade to version 5,0,0,1065, released on Yahoo!'s site on 22 May, which patches the holes.

Advertisement
The first bug is a buffer overflow affecting Messenger's handler for Uniform Resource Indicators (URIs), software installed at the system level that is used by applications like Web browsers in processing Internet addresses. A URI sent in a Messenger message, embedded in a Web site or sent in an HTML email message can trigger the overflow, allowing hackers to execute code with the security privileges of the system's user, or shut down the system.

Yahoo! warned of this bug late last month.

The second bug affects Messenger's "addview" function, allowing an attacker to send malicious script or HTML in a message, which is then rendered in a Web browser.

CERT noted that a problem with Yahoo! servers after 22 May resulted in some users downloading the vulnerable Messenger version 5,0,0,1036 instead of the new version. The problem has since been fixed. Users can check which version they have by selecting the "About Yahoo! Messenger..." option from the Help menu.

Robert Mead, coordination centre manager for AusCERT, the organisation's Australian arm, said there is a danger that "people are pretty much executing (malicious) code on users' machines... Instant messaging is very widely used, at least in non-business environments."

However, businesses may also be at risk because many workers run the software on their office PCs. CERT noted that it had not yet detected hackers actively scanning for the vulnerabilities.

According Jupiter Media Metrix, 16 percent of workers with access to the Internet will be using Instant Messaging (IM) by the end of the year, with that figure expected to reach 46 percent by the year 2005.

ZDNet Australia's Rachel Lebihan contributed to this report.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

Related Links
Yahoo! fills in Messenger hole
Previous Story: Nintendo aims high with GameCube Next Story: Teleworking growth surges ahead in the UK
Search Search for similar stories
Email Email this story to a friend
Printer friendly Printer friendly version

Latest News




Job of the day




Comment and Analysis

Rupert Goodwins Rupert Goodwins's Diary
Texting gets seal of approval


John Carroll John Carroll
The very real limitations of open source



 

Talk to us

mailroom@zdnet.co.uk
Send us your comments
News forum
Join the discussions






















 CNET Networks: CNET | GameSpot | mySimon | TechRepublic | ZDNet
Copyright © 2002 CNET Networks, Inc. All Rights Reserved.
ZDNET is a registered service mark of CNET Networks, Inc. ZDNET Logo is a service mark of CNET NETWORKS, Inc.