McAfee warns of Yahoo Messenger Webcam bug

By

Users of Yahoo's instant messaging platform are being warned to avoid webcam invites from unknown sources after a vulnerability in the platform was disclosed this week.

McAfee warns of Yahoo Messenger Webcam bug
The zero-day flaw was first published on Chinese security forums, but researchers at McAfee said this week that they recreated the flaw on Yahoo Messenger version 8.1.0.413.

The vulnerability "seems like a classic heap overflow that can be triggered when the victim accepts a webcam invite," Wei Wang, a researcher at McAfee Avert Labs, blogged on Wednesday.

McAfee said it notified Yahoo’s security team about the issue, and advised users to decline webcam invites from untrusted sources and block outgoing traffic on TCP port 5100 until the Sunnyvale, Calif.-based web giant releases a patch.

Dave Marcus, security research and communications manager at McAfee Avert Labs, told SCMagazine.com that there are no wild exploits for the flaw.

"We’re not seeing anything past proof of concept (PoC) code, so we have no reports of exploitation in the wild, but I think it’s important enough to let people know that we are monitoring the situation," he said.

"The choice of Yahoo Webcam as something to develop exploits for [is intriguing], and I think that’s a result of researchers being quick to know what’s popular out there and looking for vulnerabilities to exploit in those popular applications."

A Yahoo representative could not immediately be reached for comment.

In June, Yahoo patched two vulnerabilities in Messenger’s ActiveX control that had been disclosed by a hacker offering PoC exploit code.

A researcher using the name "Danny" had released two zero-day ActiveX exploits for Messenger’s Webcam application on the Full Disclosure mailing list.
Got a news tip for our journalists? Share it with us anonymously here.
Tags:

Most Read Articles

NSW Police to embark on $126m IT overhaul

NSW Police to embark on $126m IT overhaul

CBA looks to GenAI to assist 1200 'security champions'

CBA looks to GenAI to assist 1200 'security champions'

Australia's super funds told to assess authentication controls

Australia's super funds told to assess authentication controls

WestJet probes cyber security incident

WestJet probes cyber security incident

Log In

  |  Forgot your password?