Welcome to our website
To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.
Outlook, Outlook Express Vcard Handler Contains
Posted by Philipp Esselbach on: 02/23/2001 12:58 PM [ Print | 0 comment(s) ]
Outlook Express provides several components that are used both by it
and Outlook, if Outlook is installed on the machine. One such
component, used to process vCards, contains an unchecked buffer.
By creating a vCard and editing it to contain specially chosen data,
then sending it to another user, an attacker could cause either of
two effects to occur if the recipient opened it. In the less serious
case, the attacker could cause the mail client to fail. If this
happened, the recipient could resume normal operation by restarting
the mail client and deleting the offending mail. In the more serious
case, the attacker could cause the mail client to run code of her
choice on the userīs machine. Such code could take any desired
action, limited only by the permissions of the recipient on the
machine.
Read more/Download
and Outlook, if Outlook is installed on the machine. One such
component, used to process vCards, contains an unchecked buffer.
By creating a vCard and editing it to contain specially chosen data,
then sending it to another user, an attacker could cause either of
two effects to occur if the recipient opened it. In the less serious
case, the attacker could cause the mail client to fail. If this
happened, the recipient could resume normal operation by restarting
the mail client and deleting the offending mail. In the more serious
case, the attacker could cause the mail client to run code of her
choice on the userīs machine. Such code could take any desired
action, limited only by the permissions of the recipient on the
machine.
Read more/Download
Related Threads
02/21/2005 03:51 PM: Outlook, virus scanning and signing -Help Please (0) by aholland

