Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




fulldisclosure logo Full Disclosure mailing list archives

Re: Outlook Express - is this possible?
From: Nick FitzGerald <nick () virus-l demon co uk>
Date: Tue, 27 Jan 2004 11:16:44 +1300

"Gregh" <chows () ozemail com au> wrote:

I may just be confusing myself here so bear with me:

I believe an exploit cropped up within the last 12 months or so for OE
(version unknown) where the user has preview pane OFF and receives an email
that he doesn't actually double click on to open. However, in deleting it,
the user either web bugs himself or puts some sort of exploit in. I cant
remember whether I am confusing myself with more than one issue here but can
anyone help. Did that happen, was it possible at one stage or possible now?
<<snip>>

There was an exploitable buffer overflow in a date handling routine in 
some .DLL (MSHTML.DLL ???) that OE used for its date functions.  IIRC, 
this routine was always called while downloading and parsing messages 
(for indexing purposes?) so you could be DoS'ed (at least, if not 
owned) simply by downloading your mail.

I have a feeling that was closer to two years ago, but have not 
bothered to search the archives to check...


Regards,

Nick FitzGerald

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]