Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Can anyone summarize the security flaw that I have heard of but cannot seem to research with the ActiveX MSN chat download. If I download it now, will it have the buffer security patch?

Ok here goes,
The Systems Affected are as follows;
* Microsoft MSN Chat Control
* Microsoft MSN Messenger 4.5 and 4.6, which includes the MSN Chat control
* Microsoft Exchange Instant Messenger 4.5 and 4.6, which includes the MSN Chat controlYour concern was if you will be downloading a patched version or not?
According to the bulletin release from Microsoft:
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS02-022.asp
You will be downloading the patched version.Tech info:
For those of you who are interested the ResDLL parameter does not contain sufficent checking bounderies, thus enabling you to overflow the buffer and overright the stack most importantly the return address and the exception handlers.
-Jonathan

Thanks Jonathon. That seems simple enough. i could not narrow down the to what the patch was need: the simple chat ActiveX or the MSA messenger which I do not use.
Muchos gracias

![]() |
Norton,
|
Panda found a trojan...ca...
|

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |