Vulnerability Name: | CVE-2009-0647 (CCN-48810) | ||||||||
Assigned: | 2009-02-18 | ||||||||
Published: | 2009-02-18 | ||||||||
Updated: | 2018-10-10 | ||||||||
Summary: | msnmsgr.exe in Windows Live Messenger (WLM) 2009 build 14.0.8064.206, and other 14.0.8064.x builds, allows remote attackers to cause a denial of service (application crash) via a modified header in a packet, as possibly demonstrated by a UTF-8.0 value of the charset field in the Content-Type header line. Note: this has been reported as a format string vulnerability by some sources, but the provenance of that information is unknown. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P) 4.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:UR)
4.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Wed Feb 18 2009 - 12:56:13 CST RE: hello bug in windows live messenger Source: MITRE Type: CNA CVE-2009-0647 Source: CCN Type: Windows Live Messenger Web site Messenger - Windows Live Source: CCN Type: SA33985 Windows Live Messenger Denial of Service Weakness Source: SECUNIA Type: Vendor Advisory 33985 Source: CCN Type: OSVDB ID: 55645 Microsoft Windows Live Messenger (WLM) msnmsgr.exe Malformed Content-Type Header Remote DoS Source: BUGTRAQ Type: UNKNOWN 20090218 RE: hello bug in windows live messenger Source: BID Type: UNKNOWN 33825 Source: CCN Type: BID-33825 Windows Live Messenger Charset Data Remote Denial Of Service Vulnerability Source: VUPEN Type: Vendor Advisory ADV-2009-0466 Source: XF Type: UNKNOWN wlm-charset-dos(48810) Source: XF Type: UNKNOWN wlm-packets-dos(48810) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |