Microsoft Outlook Express Malformed Email Header Denial Of Service Vulnerability
BID:10711
Info
Microsoft Outlook Express Malformed Email Header Denial Of Service Vulnerability
| Bugtraq ID: | 10711 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2004-0215 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | This issue was announced by the vendor. |
| Vulnerable: |
Microsoft Outlook Express 6.0 Avaya S8100 Media Servers 0 Avaya S3400 Message Application Server 0 Avaya IP600 Media Servers Avaya DefinityOne Media Servers |
| Not Vulnerable: | |
Discussion
Microsoft Outlook Express Malformed Email Header Denial Of Service Vulnerability
Microsoft Outlook Express is prone to a security vulnerability when processing emails with malformed header data. A remote attacker may potentially exploit this issue to cause a persistent denial of service in the email client.
This issue is only reported to affect Outlook Express 6.0 on Windows XP platforms.
Microsoft Outlook Express is prone to a security vulnerability when processing emails with malformed header data. A remote attacker may potentially exploit this issue to cause a persistent denial of service in the email client.
This issue is only reported to affect Outlook Express 6.0 on Windows XP platforms.
Exploit / POC
Microsoft Outlook Express Malformed Email Header Denial Of Service Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Microsoft Outlook Express Malformed Email Header Denial Of Service Vulnerability
Solution:
Microsoft has released a security bulletin that includes fixes to address this issue. This security bulletin also provides cumulative patches for non-affected versions that contain various security enhancements. Users are advised to install the applicable cumulative patches even if they are running a version of Outlook Express that is not affected by the vulnerability. Please see the attached bulletin for further information.
Avaya has released an advisory that acknowledges this vulnerability for Avaya products. Avaya advise that customers follow the Microsoft recommendations to address this issue. Please see the referenced Avaya advisory at the following location for further details:
http://support.avaya.com/japple/css/japple?temp.groupID=128450&temp.selectedFamily=128451&temp.selectedProduct=154235&temp.selectedBucket=126655&temp.feedbackState=askForFeedback&temp.documentID=197331&PAGE=avaya.css.CSSLvl1Detail&executeTransaction=avaya.css.UsageUpdate()
Microsoft Outlook Express 6.0
Solution:
Microsoft has released a security bulletin that includes fixes to address this issue. This security bulletin also provides cumulative patches for non-affected versions that contain various security enhancements. Users are advised to install the applicable cumulative patches even if they are running a version of Outlook Express that is not affected by the vulnerability. Please see the attached bulletin for further information.
Avaya has released an advisory that acknowledges this vulnerability for Avaya products. Avaya advise that customers follow the Microsoft recommendations to address this issue. Please see the referenced Avaya advisory at the following location for further details:
http://support.avaya.com/japple/css/japple?temp.groupID=128450&temp.selectedFamily=128451&temp.selectedProduct=154235&temp.selectedBucket=126655&temp.feedbackState=askForFeedback&temp.documentID=197331&PAGE=avaya.css.CSSLvl1Detail&executeTransaction=avaya.css.UsageUpdate()
Microsoft Outlook Express 6.0
-
Microsoft Cumulative Security Update for Outlook Express 6 (KB823353)
http://www.microsoft.com/downloads/details.aspx?FamilyId=D5900DF1-10AB -4850-9064-3070CE1F948A&displaylang=en
References
Microsoft Outlook Express Malformed Email Header Denial Of Service Vulnerability
References:
References:
- Microsoft Security Bulletin MS04-018 (Microsoft)
- Technical Cyber Security Alert TA04-196A (CERT/CC)
- Vulnerability Note VU#869640 (CERT/CC)