Yahoo Messenger as a service cannot be terminated, but the desktop application is required to be able to be interrupted, as the security researcher discovered when he reported the overflow bug.

Julien Ahrens, an independent security researcher, has uncovered a Windows desktop flaw for Yahoo Messenger that he had privately reported to the company last year.
The bug (CVE-2014 – 7216) is a core buffer overflow flaw that can be exploited when users install malicious emoticon packages.
Ahrens discovered and documented the flaw in April 2014, but after five months of investigation by Yahoo executives, the flaw was marked as “Not Fixable” due to its upcoming EOL (End of Life).
Now, a year after his bug was ignored and there are still no updates to Yahoo Messenger for Windows, Ahrens has decided to publish his findings, doing nothing more than confirming the sad state that the once-mighty and hugely popular Yahoo! Messenger has reached.
Despite finding and properly disclosing the bug, Ahrens was not compensated for his security research under Yahoo’s Bug Bounty program.
In a private Twitter conversation, Yahoo justified its decision not to pay Ahrens because “they” seem to have changed their minds about Messenger and what it means to them. Perhaps this explains why Yahoo keeps buying companies and services and shutting them down after a year or two.
In addition to refusing to pay for a bug that falls under their own rules, Yahoo threatened Ahrens with a permanent ban from the Bug Bounty program if he didn’t disclose the bug. For an “independent” security researcher, that’s a big deal. His recent disclosure was made with the company’s approval.
