Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Microsoft MSN Messenger Malformed Invite Request Denial of Service

Microsoft's MSN Messenger is an instant messenging client for Windows based machines, based on the Passport system.

A vulnerability has been reported in some versions of MSN Messenger. Under some circumstances, it may be possible to crash the client when it receives a malformed invite request. By including a number of HTML-encoded space characters (%20) in the Invitation-Cookie field, and sending the header to a remote user, it is reportedly possible to crash a remote user's client.







 

Privacy Statement
Copyright 2008, SecurityFocus