Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

CHAT:MSN:GIF-OVERFLOW

Severity

High

Recommended

No

Recommended Action

Drop

Category

CHAT

Keywords

Gif File Buffer Overflow

Release Date

2005/04/07

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

MSN: Gif File Buffer Overflow


This signature detects attempts to exploit a known vulnerability against NSN client. Attackers can send an excessively sized GIF file through the MSN Messenger's file transfer service, which can lead to a denial-of-service condition or allow remote code execution.

Extended Description

Microsoft MSN Messenger is prone to a remote buffer-overflow vulnerability when handling malformed Graphic Interchange Format (GIF) images. This may allow an attacker to gain unauthorized access to an affected computer by executing arbitrary code, reportedly resulting in system-level compromise. Specially crafted emoticons or display pictures are likely to be used in a client-to-client attack. Other attack vectors may exist as well. MSN Messenger 6.2 and MSN Messenger 7.0 beta are vulnerable.

Affected Products

  • Microsoft MSN Messenger Service 6.2
  • Microsoft MSN Messenger Service 7.0 beta

References

  • BugTraq: 13114
  • CVE: CVE-2005-0562
  • URL: http://www.microsoft.com/technet/security/bulletin/MS05-022.mspx
  • URL: http://www.kb.cert.org/vuls/id/633446

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out