HZFQ.COM
welcome to my space
X
Non-Fiction | Stress Management | Exotic Locations | Main Course | Hair Loss | PPC Advertising | Web Design | Banking | Related articles
Welcome to:hzfq.com
Search:  
NAVIGATION - HOME

Security Bugs Squashed in Yahoo IM

Published by: webmaster 2008-11-13

Yahoo! has patched holes in its instant messenger (YIM) application after a Vietnamese researcher found security vulnerabilities that allowed unauthorized execution of programs on a user's PC via buffer overflows or Java or Visual Basic script execution.

In an advisory, researcher Phuong Nguyen said the holes allowed unauthorized script execution through the YIM content tabs. "The net impact is to allow a relatively simple opportunity to hijack users' YIM client outright, and use it to attack or intrude into YIM users supposedly private information systems," Nguyen said.

What about Bob? Glauber's NFL Blog::
Playoff seedings proposal gets squashed like a bug. Palm Beach, Fla. Security Code: Please enter the security code you see here
http://weblogs.newsday.com/sports/football/bob_blog/2008/04/playoff_seedings_proposal_gets.html
HOME
linux.debian.devel.quality-assurance (date)::
remove of debian-guide debian-guide-zh ??, Osamu Aoki; Bug squashing in Darmstadt, . Re: FWD: Squirrelmail XSS + SQL security bug?, Jeroen van Wolffelaar
http://osdir.com/ml/linux.debian.devel.quality-assurance/2004-07/
HOME
The researcher said Yahoo! was informed of the vulnerability and issued a repaired version of the popular text-based chat tool.

The Yahoo IM fix comes on the heels of a similar problem which cropped up for competitor Microsoft's instant messenger product.

Security Bugs in Oracle Lotus Products::
Security Bugs Squashed in Yahoo IM. Security Bugs Squashed in Yahoo IM 05292002 0224 PM Mozilla Offers Money for Security Bugs 08032004 0612 PM
http://www.stargeek.com/item/7137.html
HOME
iTWire - Icahn gets on board at Yahoo! - so what's next?::
Jul 22, 2008 Icahn votes his almost 5 percent of Yahoo! stock in favour of re-electing . Reply · Re: Bugs squashed, vulnerabilities patched and info
http://www.itwire.com/content/view/19559/598/
HOME
The Yahoo! IM alert, which was publicized after the company released a repaired version of the instant messenger, contained two vulnerabilities in the client. The research firm found a buffer overrun which enabled any URL beginning with "ymsgr:" to execute "ypager.exe" code. Once "ypager.exe" is called, the IM client crashed and unauthorized code could be deployed if the Yahoo IM was running on a browser.

meeblog » releases::
First, a note about the IM History notification message: we aren’t . Various Bug Fixes - As always, we’ve squashed a few bugs that have sprouted out and
http://blog.meebo.com/?cat=3
HOME
Over 1600 New AIM Smileys! - BigBlueBall Forums::
Feb 13, 2003 Thanks for reporting the bugs. On the other ones, try closing your IM window and opening a new one. Usually after a few tries it will start
http://www.bigblueball.com/forums/aim-support/15057-over-1600-new-aim-smileys.html
HOME
"If we input a string that has more than 260 bytes we will crash YIM; 264 bytes will overwrite the EBP register; four (4) more bytes will overwrite the EIP register. In total, 268 bytes are needed to cause a buffer overflow," according to the alert.

"With no proper bounds checking in the ymsgr protocol, attackers can overflow the YIM function calls "call", "sendim", "getimv", "chat", "addview", "addfriend" tags," the firm said.

It said Yahoo! removed some functionalities of the repaired IM client, including the "addview" function which enabled the instant messenger to view Web content on its own.




Liberty Alliance Adds New Members
New Wireless Push Technology Library Opens

PRINT Add to favorites
  • iona embraces mainframes eclipse in new esb
  • sun setting on community source license
  • sun s open source choice disappointing
  • the shape and cost of visual studio to come
  • popular blog defaced
  • sun s coyote project is no lone wolf
  • trustgenix to provide smbs single sign on
  • intel wants off open source listing
  • autopackage 1 0 targets developers
  • foss calls for oasis patent boycott
  • wind river donates code to open source
  • office developers hold keys to success
  • jcp lets java mustang run free
  • land bug back to bedevil microsoft servers
  • intel sets wireless mmx2 alight
  • opengear open sources kvm
  • vendors fill nt 4 0 support void
  • mozilla foundation will no longer release mozilla
  • a one stop console for administrators
  • xamlon out to connect flash to net
  • nokia launches python toolkit
  • opera ceo is sunk on browser downloads
  • report p languages better for enterprise
  • tv tell me what s on
  • microsoft web services covered with indigo
  • developers can tivo it
  • bea joins eclipse
  • osi president eric raymond steps down
  • mozilla community cashing in on bug bounties
  • ibm to add native xml for db2
  • eff throws support to anonymous internet project
  • borland s core delivers alm
  • microsoft s rudder vb6 support not done yet
  • opera gets 2d with svg
  • apache rolls cocoon 2 1 7
  • macromedia s coldfusion looks beyond the web
  • informatica hits data integration fast lane
  • java imaging code unleashed
  • red hat and meetup com cross roads
  • free windows forms code
  • microsoft intel the time for 64 bit is now
  • wanted iseries platform innovators
  • smartphone moves for avaya
  • marten mickos ceo mysql ab
  • eclipse brings web services tools to light
  • net gears for next close up
  • ibm to sprout more dev centers abroad
  • oracle programs new windows support
  • jboss pushes enterprising jems
  • solaris 10 perk to block bogus binaries
  • apple ships storage for video workgroups
  • sun s honeycomb hopes to sweeten storage
  • jason matusow microsoft shared source initiative
  • microsoft developers meet salesforce com
  • apple to open tiger
  • gates longhorn plus 64 bit equals power
  • bvrp expands in asia
  • microsoft avalon indigo to help align net
  • #If you have any other info about this subject , Please add it free.#
    Your name:
    E-mail:
    Telphone:

    Your comments:


    If you have any other info about Security Bugs Squashed in Yahoo IM , Please add it free.
     Homepage | Add to favorites | Contact us | Exchange links | LOGIN | Site map | 
    Copyright© 2008 hzfq.com        Site made:CFZ