Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Computer Support > Outlook Express and Windows Mail NNTP Memory Corruption Vulnerability

Reply
Thread Tools

Outlook Express and Windows Mail NNTP Memory Corruption Vulnerability

 
 
Leythos
Guest
Posts: n/a
 
      10-10-2007
MS07-056 : Outlook Express and Windows Mail NNTP Memory Corruption
Vulnerability

Windows ships with either the Outlook Express (OE) or the Windows Mail
(WM) email client to allow you to download and read your email.
According to Microsoft, both these email clients suffer from a memory
corruption vulnerability involving the way they handle the Network News
Transfer Protocol (NNTP) . By enticing one of your users to a specially
designed web page containing NNTP content, an attacker could exploit
this vulnerability to execute code on that user's computer with that
user's privileges. Since typical Windows users have local administrative
privileges, attackers can usually exploit this flaw to gain complete
control of Windows machines.
Microsoft rating: Critical.


--
Leythos - (remove 999 to email me)

Fight exposing kids to porn, complain about sites like PCBUTTS1.COM that
create filth and put it on the web for any kid to see: Just take a look
at some of the FILTH he's created and put on his website:
http://forums.speedguide.net/archive.../t-223485.html all exposed
to children (the link I've include does not directly display his filth).
You can find the same information by googling for 'PCBUTTS1' and
'exposed to kids'.
 
Reply With Quote
 
 
 
 
chuckcar
Guest
Posts: n/a
 
      10-10-2007
Leythos <> wrote in
news::

> MS07-056 : Outlook Express and Windows Mail NNTP Memory Corruption
> Vulnerability
>
> Windows ships with either the Outlook Express (OE) or the Windows Mail
> (WM) email client to allow you to download and read your email.
> According to Microsoft, both these email clients suffer from a memory
> corruption vulnerability involving the way they handle the Network
> News Transfer Protocol (NNTP) . By enticing one of your users to a
> specially designed web page containing NNTP content,


Is that microsoft's buzzword for mime? god knows they don't do yEnc.

an attacker could exploit
> this vulnerability to execute code on that user's computer with that
> user's privileges. Since typical Windows users have local
> administrative privileges, attackers can usually exploit this flaw to
> gain complete control of Windows machines.
> Microsoft rating: Critical.
>

Yet another result of "added capability" not doubt.



--
(setq (chuck nil) car(chuck) )
 
Reply With Quote
 
 
 
 
Meat Plow
Guest
Posts: n/a
 
      10-10-2007
On Tue, 09 Oct 2007 22:19:32 -0400, Leythos wrote:

> MS07-056 : Outlook Express and Windows Mail NNTP Memory Corruption
> Vulnerability
>
> Windows ships with either the Outlook Express (OE) or the Windows Mail
> (WM) email client to allow you to download and read your email.
> According to Microsoft, both these email clients suffer from a memory
> corruption vulnerability involving the way they handle the Network News
> Transfer Protocol (NNTP) . By enticing one of your users to a specially
> designed web page containing NNTP content, an attacker could exploit
> this vulnerability to execute code on that user's computer with that
> user's privileges. Since typical Windows users have local administrative
> privileges, attackers can usually exploit this flaw to gain complete
> control of Windows machines.
> Microsoft rating: Critical.


Wow that sucks for Windoze users.

 
Reply With Quote
 
Pennywise@DerryMaine.Gov
Guest
Posts: n/a
 
      10-10-2007
chuckcar <> wrote:

>> Windows ships with either the Outlook Express (OE) or the Windows Mail
>> (WM) email client to allow you to download and read your email.
>> According to Microsoft, both these email clients suffer from a memory
>> corruption vulnerability involving the way they handle the Network
>> News Transfer Protocol (NNTP) . By enticing one of your users to a
>> specially designed web page containing NNTP content,


>Is that microsoft's buzzword for mime? god knows they don't do yEnc.


....Newsgroups http://www.faqs.org/rfcs/rfc977.html
--

The universe is about to lose its dimension of time
http://arxivblog.com/?p=71
December 2012 mayhaps?
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
!Windows Live Mail replace Outlook Express on Windows XP and Windows Mail on Vista... Max Burke NZ Computing 8 05-18-2007 12:10 AM
Microsoft Outlook Express NNTP Response Parsing Buffer Overflow Vulnerability imhotep Computer Security 0 06-23-2006 03:44 AM
Microsoft Internet Explorer HTML Tag Memory Corruption Vulnerability Imhotep Computer Security 0 05-27-2006 04:44 AM
Microsoft Windows MSDTC Memory Corruption Vulnerability Imhotep Computer Security 2 12-20-2005 11:32 PM
Microsoft Internet Explorer COM Object Instantiation Memory Corruption Vulnerability Imhotep Computer Security 2 12-15-2005 03:03 PM



Advertisments