CVE-2004-0122
published 2004-04-15CVE-2004-0122: Microsoft MSN Messenger 6.0 and 6.1 does not properly handle certain requests, which allows remote attackers to read arbitrary files.
PriorityP335medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
22.47%
97.4th percentile
Microsoft MSN Messenger 6.0 and 6.1 does not properly handle certain requests, which allows remote attackers to read arbitrary files.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adium | adium | — | — |
| debian | pidgin | < pidgin 2.6.5-1 (bookworm) | pidgin 2.6.5-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| microsoft | msn_messenger | — | — |
| microsoft | msn_messenger | — | — |
| opensuse | opensuse | 11.0 – 11.2 | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | >= 0 < 2.6.5-1 | 2.6.5-1 |
| pidgin | pidgin | >= 0 < 2.6.5-1 | 2.6.5-1 |
| pidgin | pidgin | >= 0 < 2.6.5-1 | 2.6.5-1 |
| pidgin | pidgin | >= 0 < 2.6.5-1 | 2.6.5-1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| suse | linux_enterprise | — | — |
| suse | linux_enterprise_server | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v6ph-x2c7-6g37: Directory traversal vulnerability in slp
ghsa_unreviewed·2022-05-02·CVSS 5.0
CVE-2010-0013 [MEDIUM] CWE-22 GHSA-v6ph-x2c7-6g37: Directory traversal vulnerability in slp
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122. NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emoticon.
GHSA
GHSA-6wr2-m56m-v6hg: Microsoft MSN Messenger 6
ghsa_unreviewed·2022-04-29
CVE-2004-0122 [MEDIUM] GHSA-6wr2-m56m-v6hg: Microsoft MSN Messenger 6
Microsoft MSN Messenger 6.0 and 6.1 does not properly handle certain requests, which allows remote attackers to read arbitrary files.
OSV
CVE-2010-0013: Directory traversal vulnerability in slp
osv·2010-01-09·CVSS 5.0
CVE-2010-0013 [MEDIUM] CVE-2010-0013: Directory traversal vulnerability in slp
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122. NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emoticon.
Debian
CVE-2010-0013: pidgin - Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurp...
vendor_debian·2010·CVSS 5.0
CVE-2010-0013 [MEDIUM] CVE-2010-0013: pidgin - Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurp...
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122. NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emoticon.
Scope: local
bookworm: resolved (fixed in 2.6.5-1)
bullseye: resolved (fixed in 2.6.5-1)
forky: resolved (fixed in 2.6.5-1)
sid: resolved (fixed in 2.6.5-1)
trixie: resolved (fixed in 2.6.5-1)
Red Hat
pidgin/libpurple: MSN custom smiley request directory traversal file disclosure
vendor_redhat·2009-12-27·CVSS 5.0
CVE-2010-0013 [MEDIUM] pidgin/libpurple: MSN custom smiley request directory traversal file disclosure
pidgin/libpurple: MSN custom smiley request directory traversal file disclosure
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122. NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emoticon.
No detection rules found.
No writeups or analysis indexed.
http://www.kb.cert.org/vuls/id/688094http://www.securityfocus.com/bid/9828https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-010https://exchange.xforce.ibmcloud.com/vulnerabilities/15415https://exchange.xforce.ibmcloud.com/vulnerabilities/15427https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A844http://www.kb.cert.org/vuls/id/688094http://www.securityfocus.com/bid/9828https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-010https://exchange.xforce.ibmcloud.com/vulnerabilities/15415https://exchange.xforce.ibmcloud.com/vulnerabilities/15427https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A844
2004-04-15
Published