
Yahoo has released the latest version of its popular messaging application to fix vulnerability in the audio conferencing feature.
If exploited the hole could have given full control of a Windows computer running the vulnerable software to the hacker.
Yahoo has also stated that all messenger applications that are downloaded before March 13 are affected and all users are advised to download the latest version from the company’s web site.
For the hack to be successful the attacker was to trick a Yahoo user to visit a malicious web site. The flaw was in an ActiveX control and a small program can be typically invoked from Internet Explorer. Yahoo will also notify all users to install the update over the next couple of weeks.
Via: CNET






