PT-2002-2421 · Microsoft · Msn Messenger Service

Published

2002-12-31

·

Updated

2017-07-11

·

CVE-2002-1698

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Microsoft MSN Messenger Service versions 1.0 through 4.6
Description The issue is related to a buffer overflow that can be triggered by a long FN (font) argument in the message header, allowing remote attackers to cause a denial of service (crash).
Recommendations For Microsoft MSN Messenger Service versions 1.0 through 4.6, consider restricting the length of the FN argument in the message header to prevent the buffer overflow until a fix is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1698

Affected Products

Msn Messenger Service