Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to cause a denial of service (memory exhaustion and interrupted mail recovery) via malformed e-mail header information, possibly related to (1) long subject lines or (2) large numbers of recipients in To or CC headers.
Weaknesses in this category are related to improper management of system resources.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2007/0104 | vdb entry vendor advisory |
http://www.us-cert.gov/cas/techalerts/TA07-009A.html | third party advisory us government resource |
http://secunia.com/advisories/23674 | patch vendor advisory third party advisory |
http://www.securityfocus.com/archive/1/457274/100/0/threaded | vendor advisory |
http://linuxbox.org/pipermail/funsec/2006-March/005208.html | mailing list |
http://www.osvdb.org/31253 | vdb entry |
http://securitytracker.com/id?1017488 | patch vdb entry |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-003 | vendor advisory |
http://www.kb.cert.org/vuls/id/617436 | third party advisory us government resource |
http://www.securityfocus.com/bid/21937 | patch vdb entry |
http://osvdb.org/ref/24/24081-outlook1.txt | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A122 | signature vdb entry |
http://blogs.securiteam.com/index.php/archives/347 |