MSN Messenger Buffer Overflow in Processing Webcam Streams Lets Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1018622 |
|
SecurityTracker URL: http://securitytracker.com/id/1018622
|
|
CVE Reference:
CVE-2007-2931
(Links to External Site)
|
Updated: Sep 13 2007
|
Original Entry Date: Aug 29 2007
|
Impact:
Execution of arbitrary code via network, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes Exploit Included: Yes
|
Version(s): 6.2, 7.0, 7.5
|
Description:
A vulnerability was reported in MSN Messenger. A remote user can cause arbitrary code to be executed on the target user's system.
A remote user can create a specially crafted webcam stream that, when accepted by the target user, will trigger a heap overflow and execute arbitrary code on the target system. The code will run with the privileges of the target user.
Because the software supports one-way videochats, the target user does not need to have a webcam to be exploited.
Version 7.0.0820 on Windows 2000 SP4 is not affected.
Windows Live Messenger version 8.0 is vulnerable. Windows Live Messenger version 8.1 is not affected.
The vendor was notified in January 2007.
The original advisory is available at:
http://www.team509.com/modules.php?name=News&file=article&sid=50
A demontration exploit is available at:
http://www.team509.com/exp_msn.rar/
Wushi reported this vulnerability.
|
Impact:
A remote user can create a webcam stream that, when loaded by the target user, will execute arbitrary code on the target user's system.
|
Solution:
The vendor has issued a fixed version (7.0.0820). Users of affected versions will be prompted to upgrade when they sign in to MSN.
The Microsoft advisory is available at:
http://www.microsoft.com/technet/security/bulletin/ms07-054.mspx
Some additional information from the vendor is available at:
http://blogs.technet.com/msrc/archive/2007/09/12/technical-tips-and-insights-on-ms07-054-and-kb941835.aspx
|
Vendor URL: www.microsoft.com/technet/security/bulletin/ms07-054.mspx (Links to External Site)
|
Cause:
Boundary error
|
Underlying OS:
Windows (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Wed, 29 Aug 2007 02:52:11 -0400
Subject: MSN Messenger
|
http://www.team509.com/modules.php?name=News&file=article&sid=50
CVE-2007-2931
|
|