Check Point Reference: | CPAI-2007-204 |
Date Published: | 11 Oct 2007 |
Severity: | High |
Last Updated: | Monday 01 January, 2007 |
Source: | iDefense Advisory |
Industry Reference: | CVE-2007-3897 |
Protection Provided by: | |
Who is Vulnerable? |
|
Vulnerability Description | Several versions of Microsoft Outlook have vulnerabilities in their handling of NNTP headers that could result in arbitrary code execution. |
Update/Patch Avaliable | A patch is available through Microsoft. See MS07-056 for more information. |
Vulnerability Details | The Microsoft Outlook NNTP reader has a vulnerability in the handling of the response data to the "XHDR" command. If a malicious server sends more items than were requested, this can trigger a heap overflow resulting in remote code execution. |