Microsoft Outlook Express Malformed MIME Message Denial Of Service Vulnerability
BID:32702
Info
Microsoft Outlook Express Malformed MIME Message Denial Of Service Vulnerability
| Bugtraq ID: | 32702 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2008 12:00AM |
| Updated: | Dec 10 2008 09:01PM |
| Credit: | Bernhard 'Bruhns' Brehm at Recurity Labs |
| Vulnerable: |
Microsoft Outlook Express 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Outlook Express Malformed MIME Message Denial Of Service Vulnerability
Microsoft Outlook Express is prone to a denial-of-service vulnerability because the application fails to properly handle malformed multipart MIME messages.
An attacker can exploit this issue to crash the application during delivery.
Microsoft Outlook Express is prone to a denial-of-service vulnerability because the application fails to properly handle malformed multipart MIME messages.
An attacker can exploit this issue to crash the application during delivery.
Exploit / POC
Microsoft Outlook Express Malformed MIME Message Denial Of Service Vulnerability
An attacker may trigger this issue by constructing a malicious email message and sending it to an unsuspecting victim.
An attacker may trigger this issue by constructing a malicious email message and sending it to an unsuspecting victim.
Solution / Fix
Microsoft Outlook Express Malformed MIME Message Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Outlook Express Malformed MIME Message Denial Of Service Vulnerability
References:
References:
- DoS attacks on MIME-capable software via malformed MIME emails (Recurity Labs)
- Microsoft Outlook Express Homepage (Microsoft)
- DoS attacks on MIME-capable software via complex MIME emails ([email protected])
- Re: DoS attacks on MIME-capable software via complex MIME emails ("Vladimir '3APA3A' Dubrovin" <[email protected]>)