Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contains hex-encoded spaces (%20) in the Invitation-Cookie field.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Msn_messenger | Microsoft | 1.0 (including) | 1.0 (including) |
Msn_messenger | Microsoft | 2.0 (including) | 2.0 (including) |
Msn_messenger | Microsoft | 2.2 (including) | 2.2 (including) |
Msn_messenger | Microsoft | 3.0 (including) | 3.0 (including) |
Msn_messenger | Microsoft | 3.6 (including) | 3.6 (including) |
Msn_messenger | Microsoft | 4.0 (including) | 4.0 (including) |
Msn_messenger | Microsoft | 4.5 (including) | 4.5 (including) |
Msn_messenger | Microsoft | 4.6 (including) | 4.6 (including) |