• On TechRepublic: 10 cool USB flash drive tricks
The Download Blog
advertisement
August 16, 2007 11:39 AM PDT

Yahoo Messenger's Webcam invites may cause trouble

by Robert Vamosi

There's a new zero-day attack in progress against Yahoo Messenger users. The instant messaging solicitation invites users to open their Webcam. However, the code used in this China-based exploit causes a heap overflow to be triggered when the target accepts a Webcam invitation. That means a remote attacker could execute malicious code on a compromised machine.

The McAfee security blog recommends the following: do not accept Webcam invites from untrusted sources until a patch is released, and block outgoing traffic on TCP port 5100 on your firewall until a patch is released.

Yahoo has been informed and says it is working on a patch.

Originally posted at News Blog
As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Recent posts from The Download Blog
Apple plugs holes for domain spoofing, other attacks
Paint.NET 3.5 earns Windows 7, stability fixes
Now on Download: Bigger, better screenshots!
VMware elevates its desktop virtualization view
After 5 years, Firefox faces new challenges
Shazam iPhone app gets premium Encore
Review redux: Flixster movie app for BlackBerry
Official NASA app and a hovercraft racing game: iPhone apps of the week

Search Download Blog posts

About The Download Blog

Download.com editors cover the world of downloadable software and beyond.

Add this feed to your online news reader

The Download Blog topics