• On CBSSports.com: Mike Tyson's daughter dies in accident
The Download Blog
advertisement
August 16, 2007 11:39 AM PDT

Yahoo Messenger's Webcam invites may cause trouble

by Robert Vamosi

There's a new zero-day attack in progress against Yahoo Messenger users. The instant messaging solicitation invites users to open their Webcam. However, the code used in this China-based exploit causes a heap overflow to be triggered when the target accepts a Webcam invitation. That means a remote attacker could execute malicious code on a compromised machine.

The McAfee security blog recommends the following: do not accept Webcam invites from untrusted sources until a patch is released, and block outgoing traffic on TCP port 5100 on your firewall until a patch is released.

Yahoo has been informed and says it is working on a patch.

Originally posted at News Blog
As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Recent posts from The Download Blog
Create photo presentations and race 4x4s off road: iPhone apps of the week
Chrome OS for the clueless: What it means for real people
Manage multiple Twitter accounts with your iPhone
Silverlight 3 debuts ahead of Friday's launch
Selected Search speeds up on-page searching
Android ringtone swap: First Look video
Archive your e-mail from almost any account
An epitaph for the Web standard, XHTML 2

Search Download Blog posts

About The Download Blog

Download.com editors cover the world of downloadable software and beyond.

Add this feed to your online news reader

The Download Blog topics