The Register® — Biting the hand that feeds IT

Feeds

Yahoo! patch squashes messenger bug

Vuln researcher questions company's disclosure practices

Cloud based data management

Yahoo! bug crushers have plugged a serious hole in Yahoo! Messenger that made it possible for bad guys to remotely take control of a user's machine. The update became available less than 24 hours after an anonymous hacker posted proof-of-concept code that demonstrated how the vulnerability could be exploited.

The vulnerability stems from a buffer overflow flaw in the messenger's ActiveX control. Attackers could use it to remotely execute malicious code, or for other, less serious things, such forcing a user to log out of a chat or instant messaging session or crash Internet Explorer or another application. To carry out the attack, a miscreant must first prompt the victim to visit a booby-trapped website that contains specially crafted html code.

Ironically, Yahoo!'s own discussion of the flaw may have led to the exploit code, according to Marc Maiffret, a researcher at eEye Digital Security, the security firm that discovered the security hole. An advisory eEye posted on Wednesday warned only that "multiple flaws exist within Yahoo! Messenger which allow for remote execution of arbitrary code with minimal user interaction", eEye refused to say more publicly, out of concern the additional details would enable someone to target the holes.

That didn't stop a Yahoo! spokeswoman from disclosing in a story by Information Week that the security issue was connected to a buffer overflow in Yahoo! Messenger's ActiveX control. She revealed that it was part of the code the program uses to upload and view web cam images.

Shortly thereafter, a person going by the name of Danny posted exploit code here and in the same dispatch included a link to the Information Week article.

A Yahoo! spokeswoman didn't have an immediate comment on the company's vulnerability disclosure practices.

Maiffret, who holds up Microsoft as a model for responsible vulnerability handling, he has no doubt Yahoo! tipped its hands to hackers by giving so many details before a patch was available for download. He says companies responding to security problems should learn from the mistake.

"A lot of these non-Microsoft companies, if you will, are still behind in vulnerability response practices," he says. "This just goes to show it. There's no reason at all for a vendor to list the components." ®

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

Latest Comments

re: Model?

How many times has MS been prompted to publish a patch after a "zero day" exploit? A patch that they've been sitting on?

0
0

re: Model?

"Bad Yahoo! Released a fix in 24 hrs"

No, they didn't. They released a fix 24 hours after a hacker had already exploited the bug. They had longer than that to fix it. Not that I'm claiming they're slow or anything. But not releasing a patch for months *and* not telling anyone what to exploit seems more responsible than quickly releasing a patch, but giving hackers a fighting chance at exploiting it first.

0
0

Register! Yahoo! Headline! Missing! Exclamation Marks!

What went wrong with the headline guys? Next you'll probably forget your hatred of Kevin Warwick and write a nice review of his new book.

0
0

More from The Register

Samsung Galaxy Note 8: Proof the pen is mightier?
Sammy’s iPad Mini killer has a stylus to stab other rivals too
Microsoft lures buy-curious vixens, corduroys with a cheap fondle
Surface slab sales latest: Will no one rid Ballmer of these turbulent tabs?
First look: iOS 7 for iPad
No, Apple hasn't released it yet, but that doesn't stop intrepid devs
 breaking news
Curtain drops on Apple Store ahead of WWDC: What lies behind?
Steve Jobs watching from on high. No pressure, lads
 breaking news
Cold, dead hands of Steve Jobs slip from iPhones: The Cult of Ive is upon us
Billionaire biz baron's death clears way for uber-shiny iOS 7
Airbus imagines suitcases that find themselves
Point your mobe at your smalls to track their every move
Surprise! Intel smartphone trounces ARM in power trials
Tests show equal performance while sipping significantly less juice
Samsung plans LTE Advanced version of Galaxy S4
1Gbps download capability could stiffen drooping S4 sales forecasts
Apple said to be 'exploring' 5.7-inch iPhone
Who's the copycat this time, Mr. Cook?