Quantcast
PCWorld.com is upgrading some back-end systems. Some site features, such as user registration, may be temporarily unavailable.

Blogs

    Bugs and Fixes

  • Contributing Editor Stuart J. Johnston advises you on how to fix the latest problems affecting your operating system, your browser, your other software, and your hardware.
  • Subscribe to this blog

Bumper Crop of Instant Messaging Bugs

Stuart J. Johnston, PC World

Illustration: Harry Campbell
Chatters, beware: A rash of new bugs have hit the popular IM clients Yahoo Messenger and MSN Messenger.

The latest vulnerability could allow bad guys to feed any file to users of Yahoo Messenger, according to an e-mail alert from nCircle Network Security. This is the ninth zero-day exploit to target Yahoo's chat client this year, according to nCircle, and it leaves users vulnerable to Trojan horses and other malware. Yahoo hadn't released word of a patch at press time, but researchers believe that running Internet Explorer 7 with default security settings will likely protect you from this bug.

Yahoo did correct an earlier problem that would have allowed a complicated, two-stage attack through an ActiveX control that's part of Messenger. The exploit is difficult for hackers to pull off--meaning that it's less of a danger for you--but if you have a version of Messenger from before August 29, you should still update by going to the company's Security Updates page. 

Microsoft patched MSN Messenger and Windows Live Messenger in response to an attack that enters through a fake invitation to view someone else's Webcam. If your curiosity gets the better of you and you accept the invitation, the attacker could then do anything that you can on your machine. You are safe if you run MSN Messenger 7.0.0820 or Windows Live Messenger 8.1; otherwise, download the patch through Automatic Updates or Microsoft's Security Bulletin.

Zero-Day in Windows XP

Jonathan Sarba of GoodFellas Security Research Team revealed a flaw in a pair of files in Windows XP's system code that could allow a hacker to take total control of your computer. PCs running HP All-in-One Series Web Release software/driver installer version 2.1.0 and HP Photo & Imaging Gallery version 1.1 are particularly vulnerable to the attack because they use the portions of Windows that the attack exploits. Microsoft says that it's investigating the warning, but the software giant has yet to release a patch. Until one exists, be careful, especially if you run either piece of HP software.

  • Recommend this story?
  • 0 Yes
    0 No

"Bumper Crop of Instant Messaging Bugs" Comments

Save up to $20 on Kaspersky Security Software

Buy Kaspersky Internet Security or Anti-Virus and save up to $20. You’ll also get H&R Block Tax Software FREE (a $19.95 value).

People who read this also read:

Bugs and Fixes

All PCWorld Blogs

  • Perfect Printing Solutions Find just the right All-in-One printer for you from HP. Visit the HP Resource Center.
  • Lenovo Laptop Showcase Find out how Lenovo IdeaPads and Thinkpads balance performance and portability. Visit the Lenovo Resource Center for more info...