Microsoft Outlook Express for MacOS HTML Attachment Automatic Download Vulnerability
BID:883
Info
Microsoft Outlook Express for MacOS HTML Attachment Automatic Download Vulnerability
| Bugtraq ID: | 883 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 22 1999 12:00AM |
| Updated: | Dec 22 1999 12:00AM |
| Credit: | Publicized by Microsoft in a Security Bulletin released December 22, 1999. |
| Vulnerable: |
Microsoft Outlook Express for MacOS 5.0 |
| Not Vulnerable: | |
Discussion
Microsoft Outlook Express for MacOS HTML Attachment Automatic Download Vulnerability
Outlook Express 5 for MacOS will automatically download attachments to HTML messages, without prompting the user. This weakness does not allow for a means of forcing the user to execute any code, or place files in a specific folder, but could be used in conjunction with other attacks. Also, the default location for downloaded attachments is the desktop, where they are more likely to be seen and executed by the user.
Outlook Express 5 for MacOS will automatically download attachments to HTML messages, without prompting the user. This weakness does not allow for a means of forcing the user to execute any code, or place files in a specific folder, but could be used in conjunction with other attacks. Also, the default location for downloaded attachments is the desktop, where they are more likely to be seen and executed by the user.
Exploit / POC
Microsoft Outlook Express for MacOS HTML Attachment Automatic Download Vulnerability
see discussion
see discussion
Solution / Fix
Microsoft Outlook Express for MacOS HTML Attachment Automatic Download Vulnerability
Solution:
Microsoft has released a patch for this issue, available at:
http://www.microsoft.com/mac/download
This patch also includes a fix for a certificate expiry problem in OE5 and IE4.5 for MacOS.
Solution:
Microsoft has released a patch for this issue, available at:
http://www.microsoft.com/mac/download
This patch also includes a fix for a certificate expiry problem in OE5 and IE4.5 for MacOS.
References
Microsoft Outlook Express for MacOS HTML Attachment Automatic Download Vulnerability
References:
References: