Microsoft Outlook Express Windows Address Book File Parsing Buffer Overflow Vulnerability
BID:17459
Info
Microsoft Outlook Express Windows Address Book File Parsing Buffer Overflow Vulnerability
| Bugtraq ID: | 17459 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-0014 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 11 2006 12:00AM |
| Updated: | Apr 11 2006 08:12PM |
| Credit: | Stuart Pearson and ATmaCA are credited with the discovery of this issue. |
| Vulnerable: |
Microsoft Outlook Express 6.0 SP1 Microsoft Outlook Express 6.0 Microsoft Outlook Express 5.5 SP2 Microsoft Outlook Express 5.5 SP1 Microsoft Outlook Express 5.5 |
| Not Vulnerable: | |
Discussion
Microsoft Outlook Express Windows Address Book File Parsing Buffer Overflow Vulnerability
Microsoft Outlook Express is prone to a remote buffer-overflow vulnerability.
This vulnerability presets itself when the application processes a specially crafted Windows Address Book (.wab) file.
An attacker may exploit this issue to execute arbitrary code in the context of a user running the vulnerable application. This may result in a remote compromise.
Microsoft Outlook Express is prone to a remote buffer-overflow vulnerability.
This vulnerability presets itself when the application processes a specially crafted Windows Address Book (.wab) file.
An attacker may exploit this issue to execute arbitrary code in the context of a user running the vulnerable application. This may result in a remote compromise.
Exploit / POC
Microsoft Outlook Express Windows Address Book File Parsing Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Microsoft Outlook Express Windows Address Book File Parsing Buffer Overflow Vulnerability
Solution:
Microsoft has released fixes to address this vulnerability in supported versions of the affected software.
Microsoft Outlook Express 5.5 SP2
Microsoft Outlook Express 6.0 SP1
Microsoft Outlook Express 6.0
Solution:
Microsoft has released fixes to address this vulnerability in supported versions of the affected software.
Microsoft Outlook Express 5.5 SP2
-
Microsoft Cumulative Security Update for Outlook Express 5.5 Service Pack 2 (KB911567)
For Microsoft Windows 2000 Service Pack 4.
http://www.microsoft.com/downloads/details.aspx?familyid=E61A3D64-14FD -4976-BB03-C31CA6EE61E2&displaylang=en
Microsoft Outlook Express 6.0 SP1
-
Microsoft Cumulative Security Update for Outlook Express 6 Service Pack 1 (KB911567) - English
For Microsoft Windows XP Service Pack 1 and Microsoft Windows 2000 Service Pack 4.
http://www.microsoft.com/downloads/details.aspx?familyid=CDA93501-99CB -4F28-BB73-6438CAD081DB&displaylang=en
Microsoft Outlook Express 6.0
-
Microsoft Cumulative Security Update for Outlook Express for Windows Server 2003 (KB911567)
For Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1.
http://www.microsoft.com/downloads/details.aspx?familyid=484DE679-5505 -4196-BDD8-F7CF325AF0F5&displaylang=en -
Microsoft Cumulative Security Update for Outlook Express for Windows Server 2003 for Itanium-based Systems (KB
For Microsoft Windows Server 2003 on Itanium-based Systems and Microsoft Windows Server 2003 with SP1 for Itanium-based Systems.
http://www.microsoft.com/downloads/details.aspx?familyid=800BF687-BEE5 -478F-A025-43CD16682F31&displaylang=en -
Microsoft Cumulative Security Update for Outlook Express for Windows Server 2003 x64 Edition (KB911567)
For Microsoft Windows Server 2003 x64 Edition.
http://www.microsoft.com/downloads/details.aspx?familyid=A7B10D8F-D9D7 -4423-AA6D-C1C41D23794E&displaylang=en -
Microsoft Cumulative Security Update for Outlook Express for Windows XP (KB911567)
For Microsoft Windows XP Service Pack 2.
http://www.microsoft.com/downloads/details.aspx?familyid=0DD827BC-6FA1 -405A-933E-FB422A4E8096&displaylang=en -
Microsoft Cumulative Security Update for Outlook Express for Windows XP x64 Edition (KB911567)
For Microsoft Windows XP Professional x64 Edition.
http://www.microsoft.com/downloads/details.aspx?familyid=FF772C0B-6F98 -449D-B02E-C9C236068172&displaylang=en
References
Microsoft Outlook Express Windows Address Book File Parsing Buffer Overflow Vulnerability
References:
References: