Microsoft Outlook Express DOS Device Denial of Service Vulnerability
BID:4584
Info
Microsoft Outlook Express DOS Device Denial of Service Vulnerability
| Bugtraq ID: | 4584 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2002 12:00AM |
| Updated: | Apr 24 2002 12:00AM |
| Credit: | Discovered by ERRor <[email protected]> and 3APA3A. |
| Vulnerable: |
Microsoft Outlook Express 5.5 |
| Not Vulnerable: | |
Discussion
Microsoft Outlook Express DOS Device Denial of Service Vulnerability
A denial of service issue has been reported in Microsoft Outlook Express.
Reportedly, Outlook Express does not adequately handle unusually crafted HTML mail messages. Modifying the BGSOUND or IFRAME tag to contain a URL pointing to a DOS device, could cause Outlook Express to stop responding.
Under certain circumtances this issue may cause the system to consume CPU time.
Varying results have been reported when data is sent directly to a device, such as a denial of service, hardware failure, information disclosure or unauthorized device access.
A denial of service issue has been reported in Microsoft Outlook Express.
Reportedly, Outlook Express does not adequately handle unusually crafted HTML mail messages. Modifying the BGSOUND or IFRAME tag to contain a URL pointing to a DOS device, could cause Outlook Express to stop responding.
Under certain circumtances this issue may cause the system to consume CPU time.
Varying results have been reported when data is sent directly to a device, such as a denial of service, hardware failure, information disclosure or unauthorized device access.
Solution / Fix
Microsoft Outlook Express DOS Device Denial of Service Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Outlook Express DOS Device Denial of Service Vulnerability
References:
References: