PT-2003-1495 · Unknown · Ip Messenger For Win
Hisayuki Shinmachi
·
Published
2003-05-14
·
Updated
2017-07-11
·
CVE-2003-0288
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
IP Messenger for Win versions 2.00 through 2.02
Description:
The issue is related to a buffer overflow in the file and folder transfer mechanism. This can be triggered by a file with a long filename, allowing remote attackers to execute arbitrary code when the user saves the file.
Recommendations:
For IP Messenger for Win versions 2.00 through 2.02, consider avoiding the use of long filenames in file transfers until a fix is available. As a temporary workaround, restrict the ability to save files received through the messenger to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ip Messenger For Win