Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
DoS attacks on MIME-capable software via complex MIME emails Dec 08 2008 10:52PM
bruhns recurity-labs com (2 replies)
Re: DoS attacks on MIME-capable software via complex MIME emails Jan 27 2009 03:22PM
Dave English (dave english thus net)
In message <20081208225217.10144.qmail (at) securityfocus (dot) com [email concealed]>,
bruhns (at) recurity-labs (dot) com [email concealed] writes
...
>== Specific Software ==
>Vulnerable:
>Microsoft Outlook Express 6, Version 6.00.2900.5512
>Opera Version: 9.51 Build: 10081 System: Windows XP
>Incredimail Build ID: 5853710 Setup ID: 7 Pn: 92977368
>Norton Internet Security Version 15.5.0.23
>ESet NOD32 2.70.0039.0000
>Kaspersky Internet Security 2009; Databases from 23.07.2008
>
>Slightly affected:
>Mozilla Thunderbird Version 2.0.14 (20080421)
>
>Not vulnerable:
>Avira Antivir Search engine: v8.01.01.11, 17.07.2008
>Mutt
>Courier

Turnpike is also not vulnerable. Multikill is displayed correctly &
Nesty is partially displayed, after a warning that the message is too
complex.

>== Credit ==
>This bug was discovered by Bernhard 'Bruhns' Brehm at Recurity Labs.
>Company page: http://www.recurity-labs.com
...
--
Dave English Internet Platform Development
Senior Software & Systems Engineer Thus
a Cable&Wireless business
-----BEGIN PGP SIGNATURE-----
Version: PGP SDK 3.12.0

iQA/AwUASX8mr/6KvPRE3w75EQJq5QCgzBoLJ8rQi0C+Em0nIUc0auv2gxUAoLRa
OQi0dUKUfWzgexqNmZaWVUjF
=9VU3
-----END PGP SIGNATURE-----

[ reply ]
Re: DoS attacks on MIME-capable software via complex MIME emails Dec 09 2008 04:53PM
Vladimir '3APA3A' Dubrovin (3APA3A SECURITY NNOV RU)







 

Privacy Statement
Copyright 2009, SecurityFocus