SCF Advanced Search

  • Total Posts: 40150
  • Total Topics: 14260
  • Online Today: 697
  • Online Ever: 51419
  • (01. January 2010., 10:27:49)

Author Topic: Yahoo patches Widgets, fixes hijack bug on Windows  (Read 2575 times)

0 Members and 1 Guest are viewing this topic.


  • SCF Global Moderator
  • *****
  • Posts: 1076
  • KARMA: 22
  • Gender: Male
Yahoo patches Widgets, fixes hijack bug on Windows
« on: 27. July 2007., 21:15:16 »
Security researchers today warned that Yahoo Widgets, a platform that runs small, Web-based, gadget-like applications on computer desktops, sports a critical flaw hackers can use to hijack Windows PCs.

A bug in an ActiveX control that ships with Yahoo Widgets can be exploited to create a buffer overflow and, after that, introduce rogue code to the compromised computer. The most likely attack scenario, said Yahoo, would find attackers feeding users' links to malicious Web sites.

Yahoo issued an update to Widgets' engine earlier this week, but it was just today that Danish vulnerability tracker Secunia, which reported the bug to Yahoo, announced the flaw. Secunia pegged the problem as "extremely critical," the second-highest threat rating in its five-step scoring system.

Users have reported, however, that although they have the Widgets' automatic update mechanism turned on, they've not received notice of the patch. Yahoo acknowledged this in a security advisory posted on the Widgets site. "Over the next several weeks, users worldwide will be prompted to update to a new version of Yahoo Widgets," the alert read.

Only the Windows version of Yahoo Widgets is at risk; the Mac OS X edition does not need to be updated.

Users can download Yahoo Widgets 4.0.5 rather than wait for the update notification, Yahoo said.

Yahoo Widgets, formerly known as Konfabulator before Yahoo's acquisition of the software in 2005, competes with Windows Vista's Sidebar and with the Mac OS X's Dashboard. The number of gadgets/widgets for each of those rivals, however, falls far short of the 4,000 or so available for Yahoo's engine.
# Online Anti-Malware Scanners:,734.0.html

Samker's Computer Forum -

Yahoo patches Widgets, fixes hijack bug on Windows
« on: 27. July 2007., 21:15:16 »


With Quick-Reply you can write a post when viewing a topic without loading a new page. You can still use bulletin board code and smileys as you would in a normal post.

Name: Email:
Type the letters shown in the picture
Listen to the letters / Request another image
Type the letters shown in the picture:
Second Anti-Bot trap, type or simply copy-paste below (only the red letters)

Enter your email address to receive daily email with ' - Samker's Computer Forum' newest content:

Terms of Use | Privacy Policy | Advertising