Blog | G5 Cyber Security

18-Byte ImageMagick Hack Could Have Leaked Images From Yahoo Mail Server

Security researcher Chris Evans demonstrated an 18-byte exploit to the public that could be used to cause Yahoo servers to leak other users’ private Yahoo! Mail image attachments. The exploit abuses a security vulnerability in the ImageMagick library, which caused the service to bleed contents stored in server memory. The vulnerability actually exists in the obscure RLE (Utah Raster Toolkit Run Length Encoded) image format. The library is an open-source image processing library that lets users resize, scale, crop, watermarking and tweak images.

Source: https://thehackernews.com/2017/05/yahoo-imagemagick-hack.html

Exit mobile version