Yahoo releases critical security patch for IM
Yahoo has issued a critical security patch for Messenger to address zero-day exploits that
take advantage of vulnerabilities in its Webcam ActiveX controls.
Problem :
Messenger users' computers could be at risk if they visit malicious Web sites or view other malicious HTML code. The attackers could then exploit security flaws in the Yahoo Webcam ActiveX control, a software package that is downloaded with Messenger.
So how fast is Yahoo in patching this problem ?
eEye Digital Security discovered the flaw and reported it to Yahoo earlier this week. eEye gave the problem its highest risk rating; fellow security company Secunia did the same, labeling it "extremely critical." Yahoo issued the patch in an update on Thursday.
Download Security patch:
Yahoo's advisory on the problem states that anyone using a version of Messenger obtained before Friday should download the update.
[ zdnet ]