Vietnamese security engineer was awarded by Yahoo for discovering a serious vulnerability on Yahoo Messenger
Information from Vietnam Network Security Joint Stock Company (VSEC), Nguyen Van Luc, a security engineer of VSEC has discovered a security vulnerability on the new Yahoo Messenger version and was awarded by Yahoo.
Information from Vietnam Network Security Joint Stock Company (VSEC), Nguyen Van Luc, a security engineer of VSEC has discovered a security vulnerability on the new Yahoo Messenger version and was awarded by Yahoo.
The vulnerability was discovered quite seriously in the imageMagick image processing software related to Yahoo Messenger. Taking advantage of this vulnerability, hackers will send a maliciously formatted image file to the Yahoo Messenger system causing a memory leak of the Yahoo server. The preview image (thumbnail) will be returned and displayed in Yahoo Mesenger chat frame.
Based on this return, an attacker can collect and aggregate data on Yahoo Messenger servers and may include user data on a global scale.
All Yahoo Messenger users with tens of millions of numbers will be affected by this serious vulnerability. As of May 21, there have been over 50 million downloads of this application.
New Yahoo Messenger version.
After discovering this serious flaw, on March 13, 2018, Nguyen Van Luc informed Yahoo through an intermediary unit. After the exchange, the Yahoo company confirmed the existence of this vulnerability and identified Mr. Luc as the first to provide Yahoo. On April 12, Yahoo awarded the engineer Nguyen Van Luc about this discovery, the prize value is kept confidential.
See more:
- Thousands of Apple ID accounts are leaked because an application's server has data leaks
- Facebook awards 1 billion VND for those who find new data holes
You should read it
- How to use the new Yahoo Messenger version does not install the software
- The images are only in the memory of Yahoo Messenger
- Goodbye Yahoo! Messenger, a time to remember!
- Discover the new version of Yahoo Messenger on the web
- Yahoo chat software will remove many features on December 14
- Viruses spread through Yahoo! Messenger re-exported
- New worms appear to attack both Yahoo! Messenger, Skype
- Yahoo Messenger for iPad is available in iTunes Store of iTunes
- Facebook Messenger sticks to a vulnerability that exposes users' contacts
- Learn more about Yahoo Messenger
- Emerging new attack worms via Yahoo! Messenger
- Yahoo has returned to Yahoo Together chat application, invited to experience