Critical flaw hits Yahoo Widgets

Vulnerability could allow attackers to run code

Written by Matt Chapman

A 'highly critical' vulnerability has been discovered in Yahoo Widgets that could allow a remote attacker to run code on a user's PC.

The vulnerability is caused by a boundary error within the YDPCTL.dll ActiveX control when handling the 'GetComponentVersion()' method.

Passing a string greater than 512-bytes through an affected system could cause a stack-based buffer overflow.

Successful exploitation of the flaw would then allow arbitrary code to be executed on the system.

The vulnerability is confirmed in YDPCTL.dll version 2007.4.13.1 in Yahoo Widgets version 4.0.3, also known as 'build 178'.

However, security firm Secunia , which rated the flaw as 'highly critical', said that other versions of Yahoo Widgets may also be affected.

Users can fix the flaw manually by downloading the latest update from the Yahoo Widgets website and updating the software to version 4.0.5.

"Over the next several weeks users worldwide will be prompted to update to a new version of Yahoo Widgets on launching the application," a Yahoo security advisor said. "If you choose not to update, the vulnerability will still exist."

Yahoo Widgets are software plug-ins that allow information to be delivered to a user's desktop, including weather reports, games, radio, scoreboards, calendars and "just about anything you can imagine".

Tags:

reader comments

related articles

 

Eight April patches from Microsoft

Five critical fixes in this month's update 09 Apr 2008

Major security firms caught napping

F-Secure and Trend Micro forced to patch flaws in their own software 24 Oct 2008

Apple patches critical Safari holes

Four flaws addressed in latest update 17 Apr 2008

related whitepapers

today's top stories

Solid as a rock - business continuity in a global manufacturer

From power supply problems in Nigeria to email availability in Stockport, PZ Cussons is prepared for anything 02 Dec 2008

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

IT staff desperate to keep their jobs

Most would work longer hours for less pay 02 Dec 2008

VMware View 3 enhances virtual desktops

Virtual clients now take up less storage space and can be 'checked out' to a laptop 02 Dec 2008

Technology and privacy

Watch part one of a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 01 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Parcel being packedFeatures

Case study: eSpares and business continuity

Online electricals business has managed to decrease its downtime 02 Dec 2008

Royal Blackburn HospitalFeatures

NHS trust recovers from server overdose

Virtualisation technology breathed new life into East Lancashire's cost-intensive system 02 Dec 2008

Advertisement

Primary Navigation