CVE-2002-1831: Medium severity Microsoft MSN Messenger vulnerability
Published Dec 31, 2002
·Updated
Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contains hex-encoded spaces (%20) in the Invitation-Cookie field.
Affected Software
8 affected components
Microsoft MSN Messenger=4.6
Microsoft MSN Messenger=2.2
Microsoft MSN Messenger=2.0
Microsoft MSN Messenger=1.0
Microsoft MSN Messenger=3.6
Microsoft MSN Messenger=4.0
Microsoft MSN Messenger=4.5
Microsoft MSN Messenger=3.0
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Jun 28, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1831?
CVE-2002-1831 has a medium severity level as it allows remote attackers to cause denial of service.
2
How do I fix CVE-2002-1831?
To fix CVE-2002-1831, users should upgrade to a version of Microsoft MSN Messenger that is not affected by this vulnerability.
3
Which versions of Microsoft MSN Messenger are affected by CVE-2002-1831?
Versions 1.0 through 4.6 of Microsoft MSN Messenger are affected by CVE-2002-1831.
4
What kind of attack does CVE-2002-1831 enable?
CVE-2002-1831 enables remote denial of service attacks by sending specially crafted invite requests.
5
Is there a workaround for CVE-2002-1831 if I can’t update?
A potential workaround for CVE-2002-1831 is to restrict incoming connections to the MSN Messenger service.