Unchecked Buffer in Microsoft Outlook Express's S/MIME Parser
A buffer overrun vulnerability exists in Outlook Express’s S/MIME parser that can lead to the execution of arbitrary code on the vulnerable system.
October 17, 2002
ReportedOctober 10, 2002, by Microsoft.
VERSION AFFECTED
· Microsoft Outlook Express 6.0
· Microsoft Outlook Express 5.5
DESCRIPTION
A buffer overrun vulnerability exists in OutlookExpress’s S/MIME parser that can lead to the execution of arbitrary code onthe vulnerable system. This vulnerability stems from a vulnerability in the codethat generates a warning message when a particular error condition associatedwith digital signatures occurs. By creating a digitally signed email and editingit to introduce specific data and sending it to another user, an attacker cancause the vulnerable mail client to fail or execute arbitrary code.
VENDOR RESPONSE
The vendor, Microsoft,has released Security Bulletin MS02-058(Unchecked Buffer in Outlook Express S/MIME Parsing Could Enable SystemCompromise) to address this vulnerability and recommends that affected usersimmediately apply the patch mentioned in the bulletin.
CREDIT
Discoveredby Noam Rathaus of Beyond Security Ltd
Read more about:
MicrosoftAbout the Author
You May Also Like