Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Update: MS Battles Outlook Bug
Kevin Poulsen, SecurityFocus 2000-07-19

Upgrading Microsoft Explorer fixes a newly discovered hole in Outlook that threatens email-borne havoc.

Comments Mode:
Microslow 2000-07-19
Anonymous
Still using outlook? 2000-07-19
Anonymous (2 replies)
Still using outlook? 2000-07-20
Anonymous (2 replies)
Still using outlook? 2000-07-20
Anonymous (3 replies)
Still using outlook? 2000-07-21
Anonymous
Still using outlook? 2000-07-23
Anonymous (3 replies)
Still using outlook? 2000-07-24
Anonymous
Still using outlook? 2000-07-25
Anonymous
Problem is Outlook still suffers from the problem where if you get HTML messages, it's all too happy to download images off the internet for you to finish the message. One can only imagine how this could be used by spammers and others who seek to advertise via e-mail. "Oh, look. A hit on my webserver. Guess he/she/it read my e-mail. I can now spam them forever."

Although that feature MAY have some good uses, it's too easy to abuse. Probably a worse one is by default Outlook will run all javascript/vbscript embeded in HTML (although not with full permissions), and activex controls. And the "Restricted" zone doesn't really disable them either. This is just bad design, and I have far less tolerance for bad design than for simple buffer overflow errors.

Besides the fact this isn't the first buffer overflow in Outlook -- there used to be a long filename overflow, and there was a scriptlet.typelib/eyedog problem, which is responsible for a much more serious problem that IS happening -- the kak worm infecting OE everywhere.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/62/2680#2680
Re: Still using outlook? 2005-09-08
Roach
Still using outlook? 2000-07-24
Anonymous
Still using outlook? 2000-07-24
Anonymous
Still using outlook? 2000-07-21
Anonymous
Shame to Microsoft 2000-07-19
Anonymous (1 replies)
Shame to Microsoft 2000-07-21
Anonymous
Micro?? 2000-07-19
Anonymous
Easy to use 2000-07-20
Anonymous
Server Filtering 2000-07-20
Eric Andry <eric (at) wincom (dot) net [email concealed]> (1 replies)
Server Filtering 2000-07-24
Anonymous
Is the cure worse than the problem? 2000-07-20
Anonymous (2 replies)
Is the cure worse than the problem? 2000-07-21
Anonymous (1 replies)
Is the cure worse than the problem? 2000-07-21
Eric Andry <eric (at) wincom (dot) net [email concealed]> (1 replies)
Is the cure worse than the problem? 2000-07-24
Anonymous (1 replies)
I guess a good solution for MS is... 2000-07-20
Anonymous (2 replies)
I guess a good solution for MS is... 2000-07-21
Anonymous (1 replies)
Its so easy to use! 2000-07-21
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus