CVE-2002-1698: Buffer Overflow
Published Dec 31, 2002
·Updated
Buffer overflow in Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via a long FN (font) argument in the message header.
Affected Software
8 affected components
Microsoft MSN Messenger=1.0
Microsoft MSN Messenger=2.0
Microsoft MSN Messenger=2.2
Microsoft MSN Messenger=3.0
Microsoft MSN Messenger=3.6
Microsoft MSN Messenger=4.0
Microsoft MSN Messenger=4.5
Microsoft MSN Messenger=4.6
Event History
Dec 31, 2002
CVE Published
05:00 AM
Jun 21, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1698?
CVE-2002-1698 is considered to have a high severity due to its ability to cause a denial of service.
2
How do I fix CVE-2002-1698?
To fix CVE-2002-1698, it is recommended to upgrade to a later version of Microsoft MSN Messenger that addresses this vulnerability.
3
What are the affected versions of Microsoft MSN Messenger in CVE-2002-1698?
The affected versions in CVE-2002-1698 include Microsoft MSN Messenger versions 1.0 through 4.6.
4
What type of attack does CVE-2002-1698 allow?
CVE-2002-1698 allows remote attackers to initiate a buffer overflow that causes the application to crash.
5
Is there any workaround for CVE-2002-1698?
A potential workaround for CVE-2002-1698 is to restrict the use of MSN Messenger until an upgrade can be performed.