The OpenSSL Heartbleed security flaw was found in the cryptographic software library. Yahoo was one of the more notable websites to be affected by the catastrophically bad bug. Yahoo users passwords should be reset as a precaution, says the newly-appointed editor of Virus Bulletin. The bug appears to have been around for about two years, meaning it could have been actively exploited by unauthorised parties for a long period of time. Yahoo is not the first vendor to fix their product from this flaw, but they were far from the first.”]
Source: https://grahamcluley.com/heartbleed-bug-leak-yahoo-password/