Microsoft Outlook Express/Windows Mail共用库整数溢出漏洞

漏洞起因
边界条件错误
危险等级

 
影响系统
Microsoft Windows Mail
Microsoft Windows Live Mail 0
Microsoft Outlook Express 6.0 SP1
Microsoft Outlook Express 6.0
Microsoft Outlook Express 5.5 SP2
Microsoft Outlook Express 5.5 SP1
Microsoft Outlook Express 5.5
 
不受影响系统
 
危害
远程攻击者可以利用漏洞以应用程序权限执行任意指令。
 
攻击所需条件
攻击者必须构建恶意服务器,诱使用户使用windows邮件客户端连接。
 
漏洞信息
Microsoft Outlook Express/Windows Mail是windows系统中自带的邮件客户端。
Windows邮件客户端软件处理特殊构建的STAT应答存在整数溢出,远程未授权用户可利用漏洞引用越界内存触发内存破坏,可能以应用程序权限执行任意指令。
构建恶意服务器,诱使用户使用POP3和IMAP协议连接可触发此漏洞。
 
测试方法
 
厂商解决方案
用户可参考如下供应商提供的安全补丁:
Microsoft Windows Mail 0
Microsoft Security Update for Windows Server 2008 R2 x64 Edition (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=E2E25C02-38CE -4868-A01A-39FC7D2A4150
Microsoft Security Update for Windows Server 2008 R2 for Itanium-based Systems (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=53ED1055-B5EE -4FDE-9550-F8B401916467
Microsoft Security Update for Windows Vista for x64-based Systems (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=9A7853B5-4F9F -4467-9530-EEA2EFD504A5
Microsoft Security Update for Windows 7 for x64-based Systems (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=A70F15E1-512C -44CA-A308-928E237AC0CE
Microsoft Security Update for Windows Server 2008 for Itanium-based Systems (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=DA01AE82-895E -4739-916F-A63B9095A076
Microsoft Security Update for Windows Vista (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=A970C869-24FE -4EF4-B189-7A6BAC2411F1
Microsoft Security Update for Windows 7 (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=1F0C17BE-BA4C -4A1C-B9C3-8AC368800947
Microsoft Security Update for Windows Server 2008 x64 Edition (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=B0EAB011-5847 -44E4-BC0D-5C5355E1E8D0
Microsoft Security Update for Windows Server 2008 (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=5F77A640-247C -4ED2-9FCA-4B7344F4DC7C
Microsoft Outlook Express 5.5 SP2
Microsoft Security Update for Outlook Express 5.5 for Windows 2000 (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=661F5DE3-A593 -4961-8E8D-2777797EB5C5
Microsoft Windows Live Mail 0
Microsoft Security Update for Windows XP x64 Edition (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=44BC97BB-6F76 -4C96-AF72-69DAAEA80FFF
Microsoft Security Update for Windows Server 2008 for Itanium-based Systems (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=DA01AE82-895E -4739-916F-A63B9095A076
Microsoft Security Update for Windows 7 for x64-based Systems (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=A70F15E1-512C -44CA-A308-928E237AC0CE
Microsoft Security Update for Windows XP (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=99707C3D-A3CB -47DA-B38E-8AE0227FD703
Microsoft Security Update for Windows Server 2008 R2 for Itanium-based Systems (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=53ED1055-B5EE -4FDE-9550-F8B401916467
Microsoft Security Update for Windows Server 2008 x64 Edition (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=B0EAB011-5847 -44E4-BC0D-5C5355E1E8D0
Microsoft Security Update for Windows 7 (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=1F0C17BE-BA4C -4A1C-B9C3-8AC368800947
Microsoft Security Update for Windows Server 2008 R2 x64 Edition (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=E2E25C02-38CE -4868-A01A-39FC7D2A4150
Microsoft Security Update for Windows Vista for x64-based Systems (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=9A7853B5-4F9F -4467-9530-EEA2EFD504A5
Microsoft Security Update for Windows Server 2008 (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=5F77A640-247C -4ED2-9FCA-4B7344F4DC7C
Microsoft Security Update for Windows Vista (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=A970C869-24FE -4EF4-B189-7A6BAC2411F1
Microsoft Outlook Express 6.0 SP1
Microsoft Security Update for Outlook Express 6.0 for Windows 2000 (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=CDA75174-B535 -4559-A52D-B5EC3A1DF349
Microsoft Outlook Express 6.0
Microsoft Security Update for Windows XP (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=99707C3D-A3CB -47DA-B38E-8AE0227FD703
Microsoft Security Update for Windows Server 2003 x64 Edition (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=5678515A-97EA -4E00-8700-D3F2FCDC0EFC
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=60EF635B-CB6D -402F-B904-E69B519D797F
Microsoft Security Update for Windows Server 2003 (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=EB9742FC-0934 -4B38-9EC4-3597FC71EC00
Microsoft Security Update for Windows XP x64 Edition (KB978542)
http://www.microsoft.com/downloads/details.aspx?familyid=44BC97BB-6F76 -4C96-AF72-69DAAEA80FFF
 
漏洞提供者
Microsoft

发表评论?

0 条评论。

发表评论