Yahoo Patches Vulnerability Allowing Hackers To Eavesdrop On Emails
Yahoo has fixed a flaw in its Mail service that could have allowed hackers to eavesdrop on user emails nearly a year after the same bug was disclosed and patched. Jouko Pynnonen from Finland received $10,000 from Yahoo for disclosing the new vulnerability, which Yahoo fixed last month. The flaw concerned a cross-site scripting attack that gave an attacker the permission to read a user’s email or create a virus to infect Yahoo Mail accounts....