Yahoo fixes Messenger transfer flaw

Summary: Yahoo has fixed a bug in its instant messenger application after it was found to be vulnerable to buffer-overflow errors when receiving files, potentially leaving PCs open to attack

A serious security bug in Yahoo's Instant Messenger, which could cause a buffer-overflow error and leave users' machines open to malicious code, was finally repaired on Thursday.

A buffer overflow occurs when an application receives a string of data that is too long for it to handle. This leaves the sender of that data string in a position to load the buffer with another value, allowing malicious code to be executed instead of the original program. In this case, the error affected versions 5.6.0.1351 and earlier of Yahoo's IM client software, and was triggered when a user downloaded a file with a name that was a specific number of characters in length. A server-side fix means that users will not have to upgrade their software.

Tri Huynh, a security consultant based in Massachusetts, who claims to have discovered the problem two months ago, told ZDNet UK that the bug posed serious problems because of the ease with which PCs could be infected. "This is highly critical. When you get sent a file and you save it, you don't even need to open the file for the overflow to happen," he said.

A Yahoo spokeswoman told ZDNet UK that the company had fixed the bug in their server software on Thursday. "Upon learning of this issue, we immediately began working towards a resolution and implemented a server-side fix early on Thursday morning, eliminating the need for users to download a patch or a new version of Yahoo Messenger," she said. "We are not aware of any active exploits that have affected our users."

This is the second buffer-overflow bug that has been reported in Yahoo's popular instant messenger program in less than a month.

Topic: Security

Munir Kotadia

About Munir Kotadia

Munir first became involved with online publishing in 1998 when he joined ZDNet UK and later moved into print publishing as Chief Reporter for IT Week, part of ZDNet UK, a weekly trade newspaper targeted at Enterprise IT managers. He later moved back into online publishing as Senior News Reporter for ZDNet UK.

Munir was recognised as Australia's Best Technology Columnist at the 5th Annual Sun Microsystems IT Journalism Awards 2007. In the previous year he was named Best News Journalist at the Consensus IT Writers Awards.

He no longer uses his Commodore 64.

Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.

Talkback

3 comments
Log in or register to join the discussion
  • i sent a pic by yahoo file in the chat room of yahoo mesenger from my file -and now i do not see it in my file-where it is -it said that was in the file of yahoo file transfer server-how can get it back or see it
    anonymous
  • i tried also to send a friend a file and it aske dif i wanted to put it on the yahoo file transfer server, where does my friend go to get the file
    anonymous
  • OK. I just ended up sending a file into the Yahoo! black hole. Where does one go to either retrieve or delete the file?
    anonymous