Yahoo Messenger Flaw Highlights IM Security Issues
By NewsFactor Network | December 15, 2006
A glitch in Yahoo’s instant-messaging program has prompted the company to issue a patch for what experts have called a “highly critical” flaw.
According to a statement posted on Yahoo’s Web site, the flaw lets malicious hackers cause a buffer overflow in users’ computers. A buffer overflow is a common hack attack in which a program attempts to store too much data in the space allotted for it, causing the system to spin out of control and crash.
The Messenger overflow is accomplished by means of ActiveX, a set of Microsoft components used to enhance the features of Internet software.
If struck by the buffer overflow, users could be forcibly logged out of Messenger, or even see Internet Explorer and other software crash. While less likely, the Messenger flaw could be used to remotely plant malicious software on a user’s computer, which in turn would allow a hacker to hijack it.
IM in the Enterprise
Yahoo’s Messenger is used largely by consumers, and competes with AOL’s AIM and Microsoft’s Windows Live Messenger, among others. But even consumer instant-messaging software has seeped into the enterprise, giving I.T. departments and threat-detection experts no small number of headaches.
“In the past year, the way that large companies think about IM has changed, in the sense that it’s no longer that small groups of users can do it and be ignored by I.T.,” said Mark Levitt, program vice president for collaborative computing and the enterprise workplace at research firm IDC.
“Instead of having people just rely on Yahoo, Google, ICQ, and others, they’re increasingly deploying Microsoft’s Live Communications Server” and other business-grade IM systems, he added, to regulate and protect the way that employees use instant messaging.
Three Drivers
As with e-mail, IM has led companies to worry about the influx of virus attacks, Trojans, and other malware, not to mention the…
Topics: Tech News |
« Kenwood Media Keg reviewed | Main | Is this the iTV remote? Please, God, no »
Comments
Similar Posts
- Yahoo Marries E-Mail to Instant Messaging
Vtech’s IS6110 cordless phone touts QWERTY keypad, IM capability
Microsoft Rolls Out New Round of Patches
Macs and PCs Vulnerable to QuickTime Hack
Security Flaw Discovered in Acrobat
Researchers Focus on Mac Security
Microsoft Gears Up for VoIP Server Play
Windows Vista Flaw Not Cause for Major Concern
Microsoft Tests VoIP in Communications Server 2007
Microsoft Looks Beyond Vista Bugs
Adobe Patches Acrobat Security Flaw
IBM Releases Lotus Notes for the Mac
Apple Patches Serious QuickTime Bugs
Microsoft Warns of New Word Attack
Is AOL Instant Messaging Good for Business Use?
Apple Patches Critical QuickTime Flaw
Microsoft Confirms New Word Vulnerability
Google Shuts Hole in Desktop Search
Google Unveils Apps Premier Edition
Where To Get Free Spyware Protection
















