Microsoft Windows Live Messenger Contact List Processing Remote Denial of Service Vulnerability
BID:18639
CVE-2006-3250 |Info
Microsoft Windows Live Messenger Contact List Processing Remote Denial of Service Vulnerability
| Bugtraq ID: | 18639 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 25 2006 12:00AM |
| Updated: | Jun 26 2006 05:30PM |
| Credit: | Discovery is credited to JAAScois. |
| Vulnerable: |
Microsoft Windows Live Messenger 8.0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows Live Messenger Contact List Processing Remote Denial of Service Vulnerability
Microsoft Windows Live Messenger is reported prone to a remote denial-of-service vulnerability when handling malformed contact list (.ctt) files.
A successful attack can result in a denial of service condition by crashing the application.
Windows Live Messenger 8.0 is reported to be vulnerable. Other versions may be affected as well.
Microsoft Windows Live Messenger is reported prone to a remote denial-of-service vulnerability when handling malformed contact list (.ctt) files.
A successful attack can result in a denial of service condition by crashing the application.
Windows Live Messenger 8.0 is reported to be vulnerable. Other versions may be affected as well.
Exploit / POC
Microsoft Windows Live Messenger Contact List Processing Remote Denial of Service Vulnerability
A CTT file is available to demonstrate this issue:
A CTT file is available to demonstrate this issue:
Solution / Fix
Microsoft Windows Live Messenger Contact List Processing Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected] <mailto:[email protected]:[email protected]>.
Solution:
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected] <mailto:[email protected]:[email protected]>.
References
Microsoft Windows Live Messenger Contact List Processing Remote Denial of Service Vulnerability
References:
References:
- [Full-disclosure] Windows Live Messenger 8.0 ( Contact List *.ctt ) Heap Overflo (Michele Cicciotti [Khamsa S.A.]
) - Microsoft Technet Security (Microsoft)
- MSN Messenger Homepage (Microsoft)