Microsoft Outlook Express SMTP Over TLS Information Disclosure Vulnerability
BID:5274
Info
Microsoft Outlook Express SMTP Over TLS Information Disclosure Vulnerability
| Bugtraq ID: | 5274 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 19 2002 12:00AM |
| Updated: | Jul 19 2002 12:00AM |
| Credit: | Published by Greg Owen <[email protected]>. |
| Vulnerable: |
Microsoft Outlook Express for MacOS 5.0.3 Microsoft Outlook Express for MacOS 5.0.2 Microsoft Outlook Express for MacOS 5.0.1 Microsoft Outlook Express for MacOS 5.0 Microsoft Outlook Express for MacOS 4.5 Microsoft Outlook Express 4.72.3612 Microsoft Outlook Express 4.72.3120 Microsoft Outlook Express 4.72.2106 Microsoft Outlook Express 4.27.3110 Microsoft Outlook Express 6.0 Microsoft Outlook Express 5.5 Microsoft Outlook Express 5.0 Microsoft Outlook Express 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft Outlook Express SMTP Over TLS Information Disclosure Vulnerability
Microsoft Outlook Express is a mail client for the Microsoft Windows operating system. Outlook Express includes support for secure SMTP communications using TLS, as defined in RFC 2487.
Under TLS, it is possible for a client and server to successfully negotiate an encrypted connection without authentication. In this case, transmitted data will be properly encrypted, but the identity of the client and server are not securely defined.
Reportedly, Outlook Express does not report this condition to the end user. Sensitive information may be disclosed to a malicious server as the SMTP conversation continues, including SMTP AUTH credentials.
This behavior has been reported in Outlook Express. It is possible, however, that additional SMTP clients share this behavior.
Microsoft Outlook Express is a mail client for the Microsoft Windows operating system. Outlook Express includes support for secure SMTP communications using TLS, as defined in RFC 2487.
Under TLS, it is possible for a client and server to successfully negotiate an encrypted connection without authentication. In this case, transmitted data will be properly encrypted, but the identity of the client and server are not securely defined.
Reportedly, Outlook Express does not report this condition to the end user. Sensitive information may be disclosed to a malicious server as the SMTP conversation continues, including SMTP AUTH credentials.
This behavior has been reported in Outlook Express. It is possible, however, that additional SMTP clients share this behavior.
Solution / Fix
Microsoft Outlook Express SMTP Over TLS Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.