On mySimon: Lemony Snicket: Trouble Begins Book Set
BNET Business Network:
BNET
TechRepublic
ZDNet

August 16th, 2007

Beware of strange Yahoo Messenger webcam invites

Posted by Ryan Naraine @ 7:20 am

Categories: Botnets, Browsers, Data theft, Exploit code, Hackers, Passwords, Patch Watch, Pen testing, Responsible disclosure, Spam and Phishing, Spyware and Adware, Viruses and Worms, Vulnerability research, Zero-day attacks

Tags: McAfee Inc., Yahoo IM, Webcam, Yahoo! Inc., Ryan Naraine

Beware of strange Yahoo Messenger webcam invitesExploit code for a potentially serious vulnerability in Yahoo Messenger has been posted on the Internet, putting millions of computer users at risk of code execution attacks.

The flaw, confirmed in fully-patched versions of Yahoo Messenger, causes a heap overflow to be triggered when the target accepts a webcam invitation.

The exploit, published on a Chinese security forum, has been reproduced by researchers in McAfee’s labs. According to Dave Marcus, security research and communications manager in McAfee Avert Lab, Yahoo has been notified and is investigating.

In the absence of a patch, McAfee recommends the following:

  • Do not accept webcam invites from untrusted sources.
  • Block outgoing traffic on TCP port 5100.

“This one does require a lot of user-assisted action but a successful attack can cause full remote code execution,” Marcus said in an interview.

[UPDATE: August 16 @ 12:06 PM]  Yahoo spokeswoman Monica Ma e-mails:

Yahoo! takes security seriously and consistently employs measures to help protect our users.  Since learning of this issue, we have been actively working towards a resolution and expect to have a fix shortly.

ALSO SEE:

“High risk” flaws found in Yahoo Messenger

Exploits released for nasty Yahoo Webcam ActiveX flaws

Yahoo screws up flaw disclosure, helps exploit writer

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 1 Talkback(s)
Webcam invites  jimmccormick | 08/16/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
Reduce risk. Reduce complexity. Increase reliability.
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
Learn more >>
Keep Up With The Latest In Document Management with The DocuMentor.
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
Learn more >>
The best support in the Linux business
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
Learn more >>
Save time with automated shipping solutions
The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
Visit the UPS Business Essentials Guide
The more you simplify, the more you save
When you transition from your existing Red Hat environment to SUSE Linux Enterprise from Novell, you can recognize dramatic cost savings, perhaps as much 50%
Learn more >>
Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.
Learn more about the free, six-month trial offer>>
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here