CVE-2002-1831

Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contains hex-encoded spaces (%20) in the Invitation-Cookie field.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:msn_messenger:1.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:msn_messenger:2.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:msn_messenger:2.2:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:msn_messenger:3.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:msn_messenger:3.6:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:msn_messenger:4.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:msn_messenger:4.5:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:msn_messenger:4.6:*:*:*:*:*:*:*

History

20 Nov 2024, 23:42

Type Values Removed Values Added
References () http://online.securityfocus.com/archive/1/274086 - () http://online.securityfocus.com/archive/1/274086 -
References () http://www.iss.net/security_center/static/9161.php - () http://www.iss.net/security_center/static/9161.php -
References () http://www.securityfocus.com/bid/4827 - Exploit () http://www.securityfocus.com/bid/4827 - Exploit

Information

Published : 2002-12-31 05:00

Updated : 2024-11-20 23:42


NVD link : CVE-2002-1831

Mitre link : CVE-2002-1831

CVE.ORG link : CVE-2002-1831


JSON object : View

Products Affected

microsoft

  • msn_messenger