Blog

Yahoo! issues IM security patch (Microsoft blogging pt 2 Monday)


Tags :


If you use the Yahoo! IM client (not Trillian) then there is a patch from this week you should get, details below.  Part 2 of the Microsoft blogging I was writing will be Monday as I am busy building Lotus Workplace Messaging servers today...ugh

Yahoo Inc. this week issued a security update for Yahoo Messenger after the report earlier this week of a buffer overflow vulnerability in the instant messaging client.

Yahoo said it learned of the security issue late Tuesday and issued the patch by Wednesday afternoon. Security researcher Tri Huynh discovered a vulnerability that, if exploited, could allow a malicious Web site to run code on a user's computer, according to an advisory issued Wednesday by Danish security company Secunia.


The vulnerability stems from an error in the "yauto.dll" file, an ActiveX component of Messenger. The security hole affects Yahoo Messenger versions 5.6.0.1347 and earlier, the advisory said.