, SecurityFocus 2000-07-19
Upgrading Microsoft Explorer fixes a newly discovered hole in Outlook that threatens email-borne havoc.
Expand all |
Post comment
Still using outlook?
2000-07-19
Anonymous (2 replies)
Anonymous (2 replies)
Still using outlook?
2000-07-20
Anonymous (2 replies)
Anonymous (2 replies)
Still using outlook?
2000-07-20
Anonymous (3 replies)
Anonymous (3 replies)
Is the cure worse than the problem?
2000-07-20
Anonymous (2 replies)
Anonymous (2 replies)
Is the cure worse than the problem?
2000-07-21
Eric Andry <eric (at) wincom (dot) net [email concealed]> (1 replies)
Eric Andry <eric (at) wincom (dot) net [email concealed]> (1 replies)
I guess a good solution for MS is...
2000-07-20
Anonymous (2 replies)
Anonymous (2 replies)

Although that feature MAY have some good uses, it's too easy to abuse. Probably a worse one is by default Outlook will run all javascript/vbscript embeded in HTML (although not with full permissions), and activex controls. And the "Restricted" zone doesn't really disable them either. This is just bad design, and I have far less tolerance for bad design than for simple buffer overflow errors.
Besides the fact this isn't the first buffer overflow in Outlook -- there used to be a long filename overflow, and there was a scriptlet.typelib/eyedog problem, which is responsible for a much more serious problem that IS happening -- the kak worm infecting OE everywhere.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/articles/62/2680#2680