vendor:
Outlook Express
by:
5.5
CVSS
MEDIUM
POP Mail Download Halting
119
CWE
Product Name: Outlook Express
Affected Version From: Outlook Express
Affected Version To:
Patch Exists: YES
Related CWE:
CPE: a:microsoft:outlook_express
Platforms Tested: Windows
Outlook Express POP Mail Download Halting Vulnerability
A vulnerability in Outlook Express allows a malicious message sent to the user's mailbox to halt POP mail download. The vulnerability occurs when a line containing two dots falls at a packet boundary, causing Outlook Express to interpret the second dot as the end of message marker (EOM). This results in Outlook Express switching back to POP3 command mode and interpreting the rest of the message as a POP3 response, leading to an error message or hanging of the session.
Mitigation:
Apply the latest security updates from Microsoft to address this vulnerability.