Yahoo Messenger has a bug that can let attackers plant malicious code under the guise of sending files via the popular instant messenger, a security firm reported Friday. Danish security vendor Secunia said that Yahoo Messenger doesn't correctly display long filenames in the dialog boxes which appear when users transfer files between them.
"This could be exploited to trick users into accepting and potentially executing malicious files," said Secunia in an online alert.
A Secunia researcher spotted the vulnerability last month, and the company notified Yahoo shortly after. Thursday, Yahoo posted a Messenger update (6.0.0.1921) that fixes the problem; the new version can be downloaded from
Yahoo's Web site.
Source : TechWebNews