Microsoft Live Messenger Shared Files Denial of Service Vulnerability
BID:25795
Info
Microsoft Live Messenger Shared Files Denial of Service Vulnerability
| Bugtraq ID: | 25795 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-5144 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 24 2007 12:00AM |
| Updated: | May 07 2015 05:35PM |
| Credit: | Lostmon Lords is credited with the discovery of this vulnerability. |
| Vulnerable: |
Microsoft Windows Live Messenger 8.1 |
| Not Vulnerable: | |
Discussion
Microsoft Live Messenger Shared Files Denial of Service Vulnerability
Microsoft Live Messenger is prone to a denial-of-service vulnerability because the application fails to properly bounds-check user-supplied input.
Successfully exploiting this issue allows remote attackers to crash affected applications, denying service to legitimate users. Given the nature of this issue, remote attackers may also be able to execute code, but this has not been confirmed.
Live Messenger 8.1 is vulnerable to this issue; other versions may also be affected.
Microsoft Live Messenger is prone to a denial-of-service vulnerability because the application fails to properly bounds-check user-supplied input.
Successfully exploiting this issue allows remote attackers to crash affected applications, denying service to legitimate users. Given the nature of this issue, remote attackers may also be able to execute code, but this has not been confirmed.
Live Messenger 8.1 is vulnerable to this issue; other versions may also be affected.
Exploit / POC
Microsoft Live Messenger Shared Files Denial of Service Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Live Messenger Shared Files Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Live Messenger Shared Files Denial of Service Vulnerability
References:
References:
- MSN Messenger Homepage (Microsoft)
- Windows live Messenger malformed file overflow DoS remote exploitation. (Lostmon Lords)