Security flaws found in AOL, Yahoo IM programs

Article

Security flaws found in AOL, Yahoo IM programs

Bill Brenner, Senior News Writer

Attackers could exploit vulnerabilities in popular instant messaging programs from AOL and Yahoo to upload malicious files on targeted computers, several security firms warned Wednesday.

Danish vulnerability clearinghouse Secunia warned in its SA26786 advisory

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

that attackers could exploit a flaw in AOL Instant Messenger to execute arbitrary script code.

"Input passed to the notification window is not properly sanitized before being displayed to the user," Secunia said. "This can be exploited to execute a limited amount of arbitrary script code in the Local Zone (My Computer) context by sending a specially crafted message to another user."

Secure IM:
Quiz: Secure instant messaging: A five-question multiple choice quiz to test your understanding of the content presented in the Secure instant messaging lesson of SearchSecurity.com's Messaging Security School.

Secure instant messaging in the enterprise: Instant messaging can be a conduit through which viruses come in to and sensitive data goes out of the corporate network.

Face-off: Instant messaging in the enterprise: Is instant messaging at work a matter of pure convenience, or pure danger?

Successful exploitation requires that the target user is chatting with a different user so that the notification window is shown, and that the attacker is in the buddy list of the target user or the target user accepts the IM message from the attacker, Secunia noted. The flaw affects version 6.1.41.2 of the program, and other versions may be affected as well.

Until AOL fixes the problem, Secunia recommends users protect themselves by disabling the "New IMs arrive" option in the notifications settings and adding only trusted users to the buddy list.

Meanwhile, Cupertino, Calif.-based antivirus giant Symantec Corp. warned customers of its DeepSight threat management service that Yahoo Messenger is prone to an arbitrary file-upload vulnerability.

An ActiveX control in the program fails to adequately sanitize user-supplied input, allowing attackers to upload malicious files to an arbitrary location on a victim's computer, with the permissions of the application using the ActiveX control (typically Internet Explorer), Symantec said. Yahoo Messenger 8.1.0.421 is vulnerable and other versions may be affected as well.

As a workaround, Symantec suggested users disable active scripting in Internet Explorer or set the kill bit on CLSID:24F3EAD6-8B87-4C1A-97DA-71C126BDA08F.