First published: Tue Dec 31 2002(Updated: )
Buffer overflow in Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via a long FN (font) argument in the message header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Messenger | =1.0 | |
Microsoft Messenger | =2.0 | |
Microsoft Messenger | =2.2 | |
Microsoft Messenger | =3.0 | |
Microsoft Messenger | =3.6 | |
Microsoft Messenger | =4.0 | |
Microsoft Messenger | =4.5 | |
Microsoft Messenger | =4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1698 is considered to have a high severity due to its ability to cause a denial of service.
To fix CVE-2002-1698, it is recommended to upgrade to a later version of Microsoft MSN Messenger that addresses this vulnerability.
The affected versions in CVE-2002-1698 include Microsoft MSN Messenger versions 1.0 through 4.6.
CVE-2002-1698 allows remote attackers to initiate a buffer overflow that causes the application to crash.
A potential workaround for CVE-2002-1698 is to restrict the use of MSN Messenger until an upgrade can be performed.