PT-2005-3710 · Indiatimes · Indiatimes Messenger
Gregory R. Panakkal
·
Published
2005-09-08
·
Updated
2017-07-11
·
CVE-2005-2844
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Indiatimes Messenger version 6.0
Description
The issue is related to a buffer overflow in the MMClient.exe component, which can be triggered by a long group name argument to the
RenameGroup function in the MMClient.MunduMessenger.1 ActiveX object. This can cause a denial of service, resulting in an application crash, and potentially allow the execution of arbitrary code.Recommendations
For Indiatimes Messenger version 6.0, consider disabling the
RenameGroup function in the MMClient.MunduMessenger.1 ActiveX object as a temporary workaround to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Indiatimes Messenger