SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#617436

Microsoft Outlook vulnerable to DoS via a malformed email message

Overview

There is a vulnerability in the way Microsoft Outlook handles malformed email messages that may allow a remote, unauthenticated attacker to cause a denial of service.

I. Description

Microsoft Outlook contains a vulnerability in the way that it handles certain email message headers. According to Microsoft Security Bulletin MS07-003:

    An attacker who successfully exploited the vulnerability could send a malformed e-mail to a user of Outlook that would cause the Outlook client to fail under certain circumstances. The Outlook client would continue to fail so long as the malformed e-mail message remained on the e-mail server. The e-mail message could be deleted by an e-mail administrator, or by the user via another e-mail client such as Outlook Web Access or Outlook Express, after which point the Outlook client would again function normally.


This vulnerability affects Microsoft Outlook 2000, Outlook 2002, and Outlook 2003.

II. Impact

A remote, unauthenticated attacker may be able to cause a denial of service.

III. Solution

Apply Update

Microsoft has issued an update to address this issue. See Microsoft Security Bulletin MS07-003. Note that Microsoft has documented known issues that occur after applying this update. See Microsoft Knowledgebase article 925938 for details.

Systems Affected

VendorStatusDate NotifiedDate Updated
Microsoft CorporationVulnerable12-Jan-2007

References


http://www.microsoft.com/technet/security/Bulletin/MS07-003.mspx
http://support.microsoft.com/kb/925542/
http://support.microsoft.com/kb/931270/
http://support.microsoft.com/kb/925938
http://secunia.com/advisories/23674/
http://securitytracker.com/alerts/2007/Jan/1017488.html
http://www.securityfocus.com/bid/21937

Credit

This issue is addressed in Microsoft Security Bulletin MS07-003.

This document was written by Chris Taschner.

Other Information

Date Public:2007-01-09
Date First Published:2007-01-12
Date Last Updated:2007-01-26
CERT Advisory: 
CVE-ID(s):CVE-2006-1305
NVD-ID(s):CVE-2006-1305
US-CERT Technical Alerts: 
Metric:4.09
Document Revision:27

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader