iEntry 10th Anniversary RSS Newsletter Advertising
Join the WebProWorld Forum!
Text: Decrease Font Size Increase Font Size | Print Print Article | Share: Delicious Digg StumbleUpon Post to Twitter Post to Facebook
CommentWednesday, August 15, 2007

Yahoo Messenger Webcam Zero-Day Exposed

Online chatter about a vulnerability in Yahoo Messenger has proven accurate, as a flaw in the service's Webcam capabilities can be exploited.
Yahoo Messenger Webcam Zero-Day Exposed
Yahoo Messenger Webcam Zero-Day Exposed

Security firm McAfee revealed today that hackers in China had been discussing a zero-day exploit available for Yahoo Messenger. McAfee confirmed the exploit existed, and notified Yahoo of their findings.

A malicious webcam invite can trigger a heap overflow in Yahoo Messenger. Heap overflows have been a very common exploit condition in all kinds of software over the years.

Until Yahoo provides a fix for the problem, McAfee recommended that Yahoo Messenger users avoid accepting webcam invites from untrusted sources until this flaw has been patched. For further security, those who can block outbound traffic on TCP port 5100 should do so while Yahoo bashes out a patch.

Yahoo's Webcam function also suffered from a problem with its ActiveX Controls back in June 2007. This new problem being discussed in China is not related to the June issue, which has been patched, McAfee said in its post.

Publish A Comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
7 + 1 =
Solve this simple math problem and enter the result. E.g. for 1+3, enter 4.
SEARCH
Popular WPN Business Resources












Subscribe to WebProNews


Send me relevant info