A bug in the HTML parser in a certain Microsoft HTML library, as used in various third party products, may allow remote attackers to cause a denial of service via certain strings, as reported in GFI MailEssentials for Exchange 9 and 10, and GFI MailSecurity for Exchange 8, which causes emails to remain in IIS or Exchange mail queues.
Link | Tags |
---|---|
http://secunia.com/advisories/13708 | third party advisory |
http://www.securityfocus.com/bid/12148 | vdb entry |
http://www.csis.dk/default.asp?m=1&a=194 | vendor advisory |
http://kbase.gfi.com/showarticle.asp?id=KBID002249 | patch vendor advisory |