Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/9629 | patch vendor advisory vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15127 | vdb entry |
http://marc.info/?l=bugtraq&m=107643134712133&w=2 | mailing list |