PT-2002-2421 · Microsoft · Msn Messenger Service
Published
2002-12-31
·
Updated
2017-07-11
·
CVE-2002-1698
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft MSN Messenger Service versions 1.0 through 4.6
Description
The issue is related to a buffer overflow that can be triggered by a long FN (font) argument in the message header, allowing remote attackers to cause a denial of service (crash).
Recommendations
For Microsoft MSN Messenger Service versions 1.0 through 4.6, consider restricting the length of the FN argument in the message header to prevent the buffer overflow until a fix is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Msn Messenger Service