Web Hack List

Collected research

Facebook Messenger server random memory exposure through corrupted GIF

Facebook Messenger server random memory exposure through corrupted GIF image

Uploading a GIF whose header declares a canvas size but carries no image data made the Facebook Messenger server-side renderer return a picture filled with uninitialised memory. Repeated uploads of the same file returned different pictures, leaking fragments of server memory left by other activity; the bug paid 10,000 dollars.

Record

Document
Facebook Messenger server random memory exposure through corrupted GIF image
Researcher
Dzmitry
Published by
Blogger
Date
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Dzmitry, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .