Denial of Service in Microsoft Outlook Express
A Denial of Service (DoS) condition exists in Microsoft Outlook Express, which ships with all versions of Windows.
July 17, 2004
Reported July 13, 2004, byMicrosoft
VERSIONS AFFECTED
DESCRIPTION
A Denial of Service (DoS) condition exists in Microsoft Outlook Express, which shipswith all versions of Windows. This vulnerability is a result of a lack ofrobust verification for malformed email headers. A potential attacker couldexploit this condition by sending a specially crafted email with malformedheaders, thereby causing Outlook Express to fail. If the preview pane isenabled, the user would have to manually remove the message, then restartOutlook Express to resume functionality.
VENDOR RESPONSE
Microsoft has releasedbulletin MS04-018, "Cumulative Security Update for OutlookExpress (823353)," to address this vulnerability and recommends thataffected users apply the appropriate patch listed in the bulletin. Thisbulletin supersedes MS04-013.
CREDIT
Discovered by Microsoft.
Read more about:
MicrosoftAbout the Author
You May Also Like