Yahoo Vulnerabilities Exposed

Hackers are already exploiting Yahoo Music Jukebox vulnerabilities, it has been claimed.

The US Computer Emergency Readiness Team (US-Cert) warned that two critical flaws had been detected in the Yahoo Music Jukebox YMP Datagrid and the Yahoo Mediagrid Active X controls.

It added that the systems contained multiple stack buffer overflow vulnerabilities that could be exploited by cybercriminals.

A statement from US-Cert explained: "Successful exploitation of these vulnerabilities may allow a remote attacker to execute arbitrary code on a vulnerable system."

The organization noted that users should disable their ActiveX controls to avoid the risk.

Experts have suggested that these vulnerabilities could be susceptible to cyber attacks coming from student groups in China.

Roger Thompson, chief research officer at AVG Technologies, explained to crn.com: "In the past, the Chinese exploit developers have been very quick to seize on something like this.

"These college kids are very bright. They tend to break the initial ground and then criminal gangs who are certainly organized will borrow these exploits."