The Register®

Biting the hand that feeds IT

Yahoo! IM! in! flaw! flap!

Its buffer floweth over

Older versions of Yahoo! Messenger are subject to a security flaw that could allow crackers to run hostile code on vulnerable systems, according to security researchers.

The vulnerability stems from a buffer overflow bug in versions of Yahoo! Messenger earlier than 5.6.0.1351. The latest version (5.6.0.1358) of Yahoo! Messenger is immune to the problem but users of earlier versions reportedly cannot upgrade to the new version unless they reinstall the product.

Security researcher Tri Huynh of SentryUnion discovered the vulnerability. His advisory explains that flaw stems from a failure of earlier versions of Yahoo! Messenger in downloading files with excessively long file names.

This poor coding creates a means for malicious coders to crash machines running the application or run arbitrary code of vulnerable boxen, as explained here. ®

Free Report - "High-level Best Practices in Software Configuration Management: How to deploy SCM software to the maximum advantage"

Don’t Miss

Warning: roadworksNetbooks and Mini-Laptops

Buyer's Guide They're little and we love 'em. But which ones are best?

SSL covers security embarrassments with EV figleaf

Whitepaper Helping you know scammers from Adam

Emails show journalist rigged Wikipedia's naked shorts

Overstock's Byrne vindicated amidst economic meltdown

Warning StopYours truly, angry mob

Book extract Bringing Nothing To The Party: Cleaning up the net, one satirical vigilante page at a time