On CNET: Update software safe and spyware free
BNET Business Network:
BNET
TechRepublic
ZDNet

September 19th, 2007

Zero-day flaws surface in AOL, Yahoo IM products

Posted by Ryan Naraine @ 12:58 pm

Categories: Botnets, Browsers, Data theft, Exploit code, Hackers, Metasploit, Passwords, Patch Watch, Pen testing, Responsible disclosure, Spam and Phishing, Spyware and Adware, Zero-day attacks

Tags: Yahoo IM, AOL Instant Messenger, America Online Inc., IM, Yahoo! Inc., User, Secunia, Flaw, Exploitation, Instant Messaging

Zero-day flaws surface in AOL, Yahoo IM productsZero-day vulnerabilities in two popular instant messaging products could put millions of computer users at risk of malicious hacker attacks.

Exploit code has been released for the more serious of the two flaws — a gaping hole in Yahoo Messenger — that could expose users to code execution attacks. (Milw0rm.com code here).

This is the third major security hiccup found in Yahoo Messenger over the last few months.

Separately, Secunia has posted an alert for a security bug in AOL Instant Messenger that can be exploited by malicious people to execute arbitrary script code.

Input passed to the Notification window is not properly sanitised before being displayed to the user. This can be exploited to execute a limited amount of arbitrary script code in the Local Zone (My Computer) context by e.g. sending a specially crafted message to another user.

Successful exploitation requires that the target user is e.g. chatting with a different user so that the Notification window is shown and that the attacker is in the Buddy List of the target user or the target user accepts the IM message from the attacker.

The AIM flaw was confirmed in version 6.1.41.2. Other versions may also be affected.

Secunia recommends that AIM users disable “New IMs arrive” option in the “Notifications” settings until America Online ships a patch.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 10 Talkback(s)
Same old story
IM exploits appear so frequently that I long ago decided IM is an unacceptable risk, and I don't use it. Reports like this just reinforce that conviction.... (Read the rest)
Posted by: Greenknight_z Posted on: 09/21/07 You are currently: a Guest | | Terms of Use
Multi-Messenger Applications  John Morgan VAR2 | 09/19/07
Re: Multi-Messenger Applications  svella | 09/20/07
You are at risk in any application that uses the Microsoft HTML control.  Resuna | 09/20/07
This is ALSO a flaw in Windows.  Resuna | 09/20/07
Yes, this is a Windows flaw  tracy anne | 09/20/07
EXPLOIT CODE IS VIRUS  BALTHOR | 09/20/07
WHAT'S IN A DLL  BALTHOR | 09/20/07
SCRIPT  BALTHOR | 09/20/07
relevance?  dgrainge | 09/20/07
Same old story  Greenknight_z | 09/21/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads