Exploits exist for Yahoo IM security flaws
At least two sets of exploit code have been posted on the Internet for the security flaws in Yahoo Messenger 8 first disclosed on Wednesday by the security vendor eEye on Tuesday. The two exploits were posted on the Full Disclosure mailing list on Wednesday. One set of code shows how to cause buffer overflow in the Webcam ActiveX component. Another causes a buffer overflow in the viewer ywcvwr.dll. Both exploits were written by Danny.
This morning Yahoo released a patch for Yahoo Messenger, however, update is voluntary. Users will be prompted each time the application loads until the update is installed. Given these public exploits all Yahoo Messenger users should update to the latest release as soon as possible.





Yahoo! I'm still using YIM 7 on Windows (No crappy voice feature
or embedded search boxes) and they've not updated YIM 3 beta 1
for Mac since I got my Mac back in October, so who knows when it
will come. At the rate their going the final version of YIM 3 for Mac
should be out by the first quarter of 2009!