PT-2004-1438 · Microsoft · Outlook+1
Sasa Kos
·
Publicado
2004-03-18
·
Atualizado
2021-07-23
·
CVE-2004-0284
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer version 6.0
Microsoft Outlook version 2002
Microsoft Outlook version 2003
Description
The issue allows remote attackers to cause a denial of service, specifically CPU consumption, under certain conditions. This can be triggered by visiting a web site or opening an HTML e-mail that contains two null characters (%00) after the host name, provided that the "Do not save encrypted pages to disk" option is disabled.
Recommendations
For Microsoft Internet Explorer version 6.0, enable the "Do not save encrypted pages to disk" option to prevent exploitation.
For Microsoft Outlook version 2002, enable the "Do not save encrypted pages to disk" option to prevent exploitation.
For Microsoft Outlook version 2003, enable the "Do not save encrypted pages to disk" option to prevent exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Internet Explorer
Outlook