CERTA-2005-AVI-140
Vulnerability from certfr_avis
None
Description
Une vulnérabilité a été découverte dans le traitement des images au format GIF (Graphic Interchange Format) par MSN Messenger.
Un utilisateur mal intentionné peut, au moyen d'une image ou d'un emoticon habilement constitués, exécuter du code arbitraire à distance. A noter que seul un utilisateur faisant partie de la liste des contacts de la victime peut exploiter cette vulnérabilité.
Solution
Appliquer le correctif de l'éditeur (cf. Documentation).
NoneImpacted products
References
| Title | Publication Time | Tags | ||||||
|---|---|---|---|---|---|---|---|---|
|
||||||||
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [
{
"description": "MSN Messenger 7.0 beta.",
"product": {
"name": "N/A",
"vendor": {
"name": "N/A",
"scada": false
}
}
},
{
"description": "MSN Messenger 6.2 ;",
"product": {
"name": "N/A",
"vendor": {
"name": "N/A",
"scada": false
}
}
}
],
"affected_systems_content": null,
"content": "## Description\n\nUne vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans le traitement des images au\nformat GIF (Graphic Interchange Format) par MSN Messenger.\n\nUn utilisateur mal intentionn\u00e9 peut, au moyen d\u0027une image ou d\u0027un\nemoticon habilement constitu\u00e9s, ex\u00e9cuter du code arbitraire \u00e0 distance.\nA noter que seul un utilisateur faisant partie de la liste des contacts\nde la victime peut exploiter cette vuln\u00e9rabilit\u00e9.\n\n## Solution\n\nAppliquer le correctif de l\u0027\u00e9diteur (cf. Documentation).\n",
"cves": [],
"initial_release_date": "2005-04-13T00:00:00",
"last_revision_date": "2005-04-13T00:00:00",
"links": [
{
"title": "R\u00e9f\u00e9rence CVE CAN-2005-0562 :",
"url": "http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0562"
}
],
"reference": "CERTA-2005-AVI-140",
"revisions": [
{
"description": "version initiale.",
"revision_date": "2005-04-13T00:00:00.000000"
}
],
"risks": [
{
"description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
}
],
"summary": null,
"title": "Vuln\u00e9rabilit\u00e9 dans MSN Messenger",
"vendor_advisories": [
{
"published_at": null,
"title": "Bulletin de s\u00e9curit\u00e9 Microsoft MS05-022 du 12 avril 2005",
"url": "http://www.microsoft.com/technet/security/bulletin/MS05-022.mspx"
}
]
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…