Over the next several weeks, users worldwide will be prompted to update to a new version of Yahoo! Messenger upon signing into the service. If you choose not to update and you have not updated via this page or at messenger.yahoo.com, the vulnerability will still exist.
Yahoo has a very good track record of fixing security issues quickly. However, I feel it is not proactive enough in communicating the security advisories to their users. For instance, for the current issues, there is no notice or link on the Yahoo Messenger
home page or any other part of the website asking users to install the urgent security upgrade. You won't find the advisory unless you are looking for it.
Update (10th June): I just noticed that Yahoo has now added a prominent "Security Update" notice to the Yahoo Messenger
home page. Good work, Yahoo!
Signing Off,
Masood