Unchecked Buffer in Microsoft Outlook Express's S/MIME Parser

A buffer overrun vulnerability exists in Outlook Express’s S/MIME parser that can lead to the execution of arbitrary code on the vulnerable system.

Ken Pfeil

October 17, 2002

2 Min Read
ITPro Today logo

ReportedOctober 10, 2002, by Microsoft.

 

 

VERSION AFFECTED

 

·        Microsoft Outlook Express 6.0

·        Microsoft Outlook Express 5.5

 

 

DESCRIPTION

 

A buffer overrun vulnerability exists in OutlookExpress’s S/MIME parser that can lead to the execution of arbitrary code onthe vulnerable system. This vulnerability stems from a vulnerability in the codethat generates a warning message when a particular error condition associatedwith digital signatures occurs. By creating a digitally signed email and editingit to introduce specific data and sending it to another user, an attacker cancause the vulnerable mail client to fail or execute arbitrary code.

 

VENDOR RESPONSE

 

The vendor, Microsoft,has released Security Bulletin MS02-058(Unchecked Buffer in Outlook Express S/MIME Parsing Could Enable SystemCompromise) to address this vulnerability and recommends that affected usersimmediately apply the patch mentioned in the bulletin.

 

CREDIT

Discoveredby Noam Rathaus of Beyond Security Ltd

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like