Yahoo today said it has fixed a vulnerability discovered in Yahoo Mail that would have allowed an attacker to gain control of the victim’s Yahoo Identity. Security vendor Cenzic discovered the flaw last month and reported it to Yahoo, which fixed it on June 13, according to the company.
Yahoo says it has fixed a vulnerability in Yahoo Mail that might have allowed savvy hackers to steal a victim’s Yahoo identity and gain access to private information (Compare Data Leak Protection products).
Discovered by security vendor Cenzic last month, the underlying problem was a cross-site scripting (XSS) vulnerability that affected its current version of Yahoo Messenger and its new Yahoo Mail client Version 9, still in beta.
Cenzic vice president of marketing Mandeep Khera said the fix to the XSS vulnerability involves necessary changes in Yahoo servers, so users don’t have to download new Yahoo applications. “We don’t know how many users might have been exploited before this was fixed,” he said. “Potentially this was huge in terms of identity theft.”
“We are aware of the cross-site scripting vulnerability recently discovered in Yahoo Mail and we have completely resolved the issue as of June 13,” said Yahoo spokeswoman Kelley Podboy. “To our knowledge, the vulnerability was not exploited and users were not impacted. Yahoo takes user security very seriously as we continue our efforts to combat potential threats.”
Cenzic described how an attacker would have exploited the cross-site scripting vulnerability in Yahoo Mail prior to June 13. According to Cenzic, the attacker would be using the Yahoo Messenger desktop application 8.1.0.209 while chatting with the victim. The victim would need to be using the Messenger support in the new Yahoo Mail Web application.
A new chat tab would open in the victim’s browser. During the chat, the attacker could change their status to “invisible,” causing a message of “offline” in the chat tab of the victim. During this change of status, a savvy attacker could then send a custom message containing a malicious string in the form of a status message of “online,” with the script executed in the context of Yahoo Mail on the victim’s machine.
This would have allowed the attacker to get access to the victim’s session ID, and in turn steal their Yahoo identity, as well as exposing personal information stored in the Yahoo account.
“This vulnerability exposed millions of Yahoo users to the possibility of identity theft,” Khera pointed out.
Cenzic analysts alerted Yahoo to the findings of the cross-site scripting vulnerability last month, and Yahoo, which says it corrected the problem in June, is publicly disclosing the matter today.




