Overview
Buffer Overflows in several MIME headers affect a large number of electronic mail clients.
Description
A variety of electronic mail clients (circa 1998) are vulnerable to buffer overflow attacks in the code that processes MIME headers. See the vendor statements referenced below for details specific to each mail client. |
Impact
An intruder can crash vulnerable mail clients, or use them to execute arbitrary code with the privileges of the user reading the mail. |
Solution
Fixing the problem requires modifying each email client with an appropriate patch from the vendor. |
There are several things that can be done to mitigate the risk if a patch cannot be installed. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.microsoft.com/security/bulletins/ms98-008.htm
- http://www.netscape.com/products/security/resources/bugs/longfile.html
- http://www.ciac.org/ciac/MIMEfaq.html
- http://www.ciac.org/ciac/bulletins/i-077a.shtml
- ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-98.02.Outlook.buffer.overflow
- http://www.sjmercury.com/business/tech/docs/security072898.htm
Acknowledgements
This document was written by Shawn V Hernan.
Other Information
CVE IDs: | None |
CERT Advisory: | CA-1998-10 |
Severity Metric: | 81.00 |
Date Public: | 1998-07-27 |
Date First Published: | 2001-09-20 |
Date Last Updated: | 2003-04-11 22:52 UTC |
Document Revision: | 7 |