Microsoft Outlook Express Spoofable File Extensions Vulnerability
BID:5277
Info
Microsoft Outlook Express Spoofable File Extensions Vulnerability
| Bugtraq ID: | 5277 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 20 2002 12:00AM |
| Updated: | Jul 20 2002 12:00AM |
| Credit: | Vulnerability discovery credited to Matthew Murphy <[email protected]>. |
| Vulnerable: |
Microsoft Outlook Express 6.0 Microsoft Outlook Express 5.5 Microsoft Outlook Express 5.0 |
| Not Vulnerable: | |
Discussion
Microsoft Outlook Express Spoofable File Extensions Vulnerability
It is possible for a malicious user, sending email via a mail agent capable of manipulating the MIME headers, to spoof file extensions for users of Outlook Express. For example, an .exe file can be made to look like a .txt (or other seemingly harmless file type) file in the attachment list.
When including a certain string of characters between the filename and the actual file extension, Outlook Express will display the specified misleading file extension type.
The end result is that an attacker is able to entice a user to open or save files of arbitrary types to their local system.
It is possible for a malicious user, sending email via a mail agent capable of manipulating the MIME headers, to spoof file extensions for users of Outlook Express. For example, an .exe file can be made to look like a .txt (or other seemingly harmless file type) file in the attachment list.
When including a certain string of characters between the filename and the actual file extension, Outlook Express will display the specified misleading file extension type.
The end result is that an attacker is able to entice a user to open or save files of arbitrary types to their local system.
Exploit / POC
Microsoft Outlook Express Spoofable File Extensions Vulnerability
The following example was made available by Matthew Murphy <[email protected]>:
The following example was made available by Matthew Murphy <[email protected]>:
Solution / Fix
Microsoft Outlook Express Spoofable File Extensions Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Outlook Express Spoofable File Extensions Vulnerability
References:
References: