New zero-day bug smacks Yahoo Messenger's webcam
A bug in Yahoo Messenger that first surfaced on a Chinese security forum can be used to hack a Windows PC, McAfee Inc. researchers confirmed today.
The vulnerability, apparently a heap-overflow bug, can be exploited by duping a user into accepting a malicious webcam invitation, said Wei Wang, a Beijing-based researcher at McAfee's Avert Labs.
"We got a chance to dig a bit deeper into this and were able to reproduce the vulnerability on Yahoo Messenger Version 8.1.0.413 based on the information provided in the forum," Wei said on the Avert Labs blog.