First published: Thu Feb 19 2009(Updated: )
msnmsgr.exe in Windows Live Messenger (WLM) 2009 build 14.0.8064.206, and other 14.0.8064.x builds, allows remote attackers to cause a denial of service (application crash) via a modified header in a packet, as possibly demonstrated by a UTF-8.0 value of the charset field in the Content-Type header line. NOTE: this has been reported as a format string vulnerability by some sources, but the provenance of that information is unknown.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft MSN Messenger | =2009 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0647 has a medium severity rating as it can lead to a denial of service through application crashes.
To fix CVE-2009-0647, update to the latest version of Windows Live Messenger or disable the application until a patch is available.
CVE-2009-0647 affects Microsoft Windows Live Messenger 2009 build 14.0.8064.206 and other builds in the 14.0.8064.x range.
CVE-2009-0647 is associated with a denial of service attack that exploits modified headers in packets.
Yes, CVE-2009-0647 can allow remote attackers to crash the application through crafted network packets.