Microsoft Outlook Express And Windows Mail Common Library Integer Overflow Vulnerability
BID:39927
Info
Microsoft Outlook Express And Windows Mail Common Library Integer Overflow Vulnerability
| Bugtraq ID: | 39927 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-0816 |
| Remote: | Yes |
| Local: | No |
| Published: | May 11 2010 12:00AM |
| Updated: | May 12 2010 05:22PM |
| Credit: | Microsoft |
| Vulnerable: |
Microsoft Windows Mail 0 Microsoft Windows Live Mail 0 Microsoft Outlook Express 6.0 SP1 Microsoft Outlook Express 6.0 Microsoft Outlook Express 5.5 SP2 Microsoft Outlook Express 5.5 SP1 Microsoft Outlook Express 5.5 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Messaging Application Server 0 Avaya Meeting Exchange - Webportal 6.0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 |
| Not Vulnerable: | |
Discussion
Microsoft Outlook Express And Windows Mail Common Library Integer Overflow Vulnerability
Microsoft Outlook Express and Windows Mail are prone to a remote integer-overflow vulnerability because the applications fail to perform boundary checks on integer values.
Successfully exploiting this issue will allow an attacker to execute arbitrary code with the privileges of the currently logged-in user. Failed exploit attempts will result in a denial-of-service condition.
Microsoft Outlook Express and Windows Mail are prone to a remote integer-overflow vulnerability because the applications fail to perform boundary checks on integer values.
Successfully exploiting this issue will allow an attacker to execute arbitrary code with the privileges of the currently logged-in user. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Microsoft Outlook Express And Windows Mail Common Library Integer Overflow Vulnerability
The following proof-of-concept is available:
The following proof-of-concept is available:
Solution / Fix
Microsoft Outlook Express And Windows Mail Common Library Integer Overflow Vulnerability
Solution:
The vendor released patches and an advisory. Please see the references for more information.
Microsoft Outlook Express 5.5 SP2
Microsoft Outlook Express 6.0
Microsoft Windows Live Mail 0
Microsoft Windows Mail 0
Microsoft Outlook Express 6.0 SP1
Solution:
The vendor released patches and an advisory. Please see the references for more information.
Microsoft Outlook Express 5.5 SP2
-
Microsoft Security Update for Outlook Express 5.5 for Windows 2000 (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=661F5DE3-A593 -4961-8E8D-2777797EB5C5
Microsoft Outlook Express 6.0
-
Microsoft Security Update for Windows Server 2003 (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=EB9742FC-0934 -4B38-9EC4-3597FC71EC00 -
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=60EF635B-CB6D -402F-B904-E69B519D797F -
Microsoft Security Update for Windows Server 2003 x64 Edition (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=5678515A-97EA -4E00-8700-D3F2FCDC0EFC -
Microsoft Security Update for Windows XP (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=99707C3D-A3CB -47DA-B38E-8AE0227FD703 -
Microsoft Security Update for Windows XP x64 Edition (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=44BC97BB-6F76 -4C96-AF72-69DAAEA80FFF
Microsoft Windows Live Mail 0
-
Microsoft Security Update for Windows 7 (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=1F0C17BE-BA4C -4A1C-B9C3-8AC368800947 -
Microsoft Security Update for Windows 7 for x64-based Systems (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=A70F15E1-512C -44CA-A308-928E237AC0CE -
Microsoft Security Update for Windows Server 2008 (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=5F77A640-247C -4ED2-9FCA-4B7344F4DC7C -
Microsoft Security Update for Windows Server 2008 for Itanium-based Systems (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=DA01AE82-895E -4739-916F-A63B9095A076 -
Microsoft Security Update for Windows Server 2008 R2 for Itanium-based Systems (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=53ED1055-B5EE -4FDE-9550-F8B401916467 -
Microsoft Security Update for Windows Server 2008 R2 x64 Edition (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=E2E25C02-38CE -4868-A01A-39FC7D2A4150 -
Microsoft Security Update for Windows Server 2008 x64 Edition (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=B0EAB011-5847 -44E4-BC0D-5C5355E1E8D0 -
Microsoft Security Update for Windows Vista (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=A970C869-24FE -4EF4-B189-7A6BAC2411F1 -
Microsoft Security Update for Windows Vista for x64-based Systems (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=9A7853B5-4F9F -4467-9530-EEA2EFD504A5 -
Microsoft Security Update for Windows XP (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=99707C3D-A3CB -47DA-B38E-8AE0227FD703 -
Microsoft Security Update for Windows XP x64 Edition (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=44BC97BB-6F76 -4C96-AF72-69DAAEA80FFF
Microsoft Windows Mail 0
-
Microsoft Security Update for Windows 7 (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=1F0C17BE-BA4C -4A1C-B9C3-8AC368800947 -
Microsoft Security Update for Windows 7 for x64-based Systems (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=A70F15E1-512C -44CA-A308-928E237AC0CE -
Microsoft Security Update for Windows Server 2008 (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=5F77A640-247C -4ED2-9FCA-4B7344F4DC7C -
Microsoft Security Update for Windows Server 2008 for Itanium-based Systems (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=DA01AE82-895E -4739-916F-A63B9095A076 -
Microsoft Security Update for Windows Server 2008 R2 for Itanium-based Systems (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=53ED1055-B5EE -4FDE-9550-F8B401916467 -
Microsoft Security Update for Windows Server 2008 R2 x64 Edition (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=E2E25C02-38CE -4868-A01A-39FC7D2A4150 -
Microsoft Security Update for Windows Server 2008 x64 Edition (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=B0EAB011-5847 -44E4-BC0D-5C5355E1E8D0 -
Microsoft Security Update for Windows Vista (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=A970C869-24FE -4EF4-B189-7A6BAC2411F1 -
Microsoft Security Update for Windows Vista for x64-based Systems (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=9A7853B5-4F9F -4467-9530-EEA2EFD504A5
Microsoft Outlook Express 6.0 SP1
-
Microsoft Security Update for Outlook Express 6.0 for Windows 2000 (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=CDA75174-B535 -4559-A52D-B5EC3A1DF349
References
Microsoft Outlook Express And Windows Mail Common Library Integer Overflow Vulnerability
References:
References:
- Microsoft Outlook Express Homepage (Microsoft)
- Windows Mail Product Page (Microsoft Corporation)
- {PRL} Microsoft Windows Outlook Express and Windows Mail Integer Overflow (Francis Provencher
) - ASA-2010-140 MS10-030 Vulnerability in Outlook Express and Windows Mail Could Al (Avaya)
- Microsoft Security Bulletin MS10-030 (Microsoft)