MS02-058: unchecked buffer in Outlook Express S/MIME parsing could enable system compromise. (Microsoft).(Brief Article)

Information Systems Auditor, December, 2002

Issue

To allow for verification of the authenticity of mail messages, Microsoft Outlook Express supports digital signing of messages through S/MIME.

A buffer overrun vulnerability lies in the code that generates the warning message when a particular error condition associated with digital signatures occurs.

By creating a digitally signed e-mail and editing it to introduce specific data, then sending it to other users, attackers could cause either of two effects to occur if the recipients opened or previewed it.

In the less serious case, the attackers could cause the e-mail client to fail. If this happened, the recipients could resume normal operation by restarting the e-mail client and deleting the offending mail.

In the...

Premium Content Partnership | HighBeam Research provides an in-depth online archive library of reference works. HighBeam Research

 

BNET TalkbackShare your ideas and expertise on this topic

Please add your comment:

  1. You are currently: a Guest |
  2.  

Basic HTML tags that work in comments are: bold (<b></b>), italic (<i></i>), underline (<u></u>), and hyperlink (<a href></a)

advertisement
advertisement
  • Click Here
  • Click Here
  • Click Here
advertisement