Search Help:  
 
Enter keywords to search help.

Yahoo! Music Jukebox Security Update

How do I get the Security Update?

To get the updated version of the Yahoo! Music Jukebox with the security patches, simply launch the application on your computer and you will be prompted to install the update. You can also download the updated version by visiting our website: http://music.yahoo.com/jukebox.

Canadian users can download the jukebox here.

How long will it take?

The update should take no more than a few minutes, although the exact time depends on the speed of your Internet connection.

Who is affected?

If your computer has any version of Yahoo! Music Jukebox earlier than 2.2.2.058 installed, you are affected.

What if I don't install the update?

If you choose not to update, the vulnerability will still exist on your computer, whether or not you run the Yahoo! Music Jukebox application. You will be prompted to install the update each time you run the Yahoo! Music Jukebox application. If you do not install the update when prompted, the application will close and you will not be able to access the Jukebox services.

What is the security issue?

The security issues are buffer overflow vulnerabilities in two ActiveX components installed with the Yahoo! Music Jukebox product. Successful exploitation allows execution of arbitrary code when a user visits a malicious website.

How was this discovered?

The Yahoo! Music team was recently made aware of these vulnerabilities in the Yahoo! Music Jukebox. Examples of how these vulnerabilities could be exploited were posted on the internet. Yahoo! takes security seriously. Upon notification of the vulnerabilities we immediately began corrective action.

Was this article helpful?

Yes   No
Click to contact Customer Care for further assistance.