(3 votes)
MS Outlook Patch MS01-020 (523Kb)
I know I don't usually put patches in here, but this one is a must, especially if you deal with mass amounts of email as I do.
Because HTML e-mail is simply a Web page, Internet Explorer (IE) can render it and open binary attachments in a way that is appropriate to its MIME type. However, a flaw exists in the type of processing that is specified for certain unusual MIME types. If an attacker created an HTML e-mail containing an executable attachment, then modified the MIME header information to specify that the attachment was one of the unusual MIME types that Internet Explorer handles incorrectly, IE would launch the attachment automatically when it rendered the e-mail.
Attackers could use this vulnerability in either of two scenarios. They could host an affected HTML e-mail on a Web site and try to persuade another user to visit it, at which point script on a Web page could open the mail and initiate the executable. Alternatively, they could send the HTML mail directly to the user. In either case, the executable attachment, if it ran, would be limited only by user's permissions on the system.
The vulnerability could not be exploited if File Downloads have been disabled in the Security Zone in which the e-mail is rendered. This is not a default setting in any zone, however.
Because HTML e-mail is simply a Web page, Internet Explorer (IE) can render it and open binary attachments in a way that is appropriate to its MIME type. However, a flaw exists in the type of processing that is specified for certain unusual MIME types. If an attacker created an HTML e-mail containing an executable attachment, then modified the MIME header information to specify that the attachment was one of the unusual MIME types that Internet Explorer handles incorrectly, IE would launch the attachment automatically when it rendered the e-mail.
Attackers could use this vulnerability in either of two scenarios. They could host an affected HTML e-mail on a Web site and try to persuade another user to visit it, at which point script on a Web page could open the mail and initiate the executable. Alternatively, they could send the HTML mail directly to the user. In either case, the executable attachment, if it ran, would be limited only by user's permissions on the system.
The vulnerability could not be exploited if File Downloads have been disabled in the Security Zone in which the e-mail is rendered. This is not a default setting in any zone, however.
Detailinfos
MY MS Outlook Patch MS01-020 (523Kb)
Permalink für Deine Homepage
Du kannst der Erste sein...
Sei der erste, der einen Kommentar zur Software MS Outlook Patch MS01-020 (523Kb) hinterläßt. Kommentare sollen anderen helfen sich einen ersten Eindruck über das Programm zu verschaffen bevor man den Download beginnt. Es geht schnell und unkompliziert.Ausfüllen -> abschicken -> fertig.
Jetzt den ersten Kommentar zu MS Outlook Patch MS01-020 (523Kb) verfassen.
Auch interessante Software?
Battlefield 1942 Retail Blood Patch v1.2 (89 KB)
Dieser Patch bringt Blut in der Retail Version (alle Sprachen) von Battlefield 1942, er funktioniert mit der Retail Multiplayer Version, die Server Ve...
Far Cry - Patch 1.1 von Version 1.0 dt.
Update 1.1 (27 MB):
Far Cry - Patch 1.1 von Version 1.0 dt.
HINWEIS: Dieses Update wird NICHT benötigt für die neue deutsche Version!
Was genau ge...
PatchFactory
Full-featured byte-level patching system for bandwidth-efficient software updating. PatchFactory provides a flexible, reliable and effective method to...
Outlook Recovery
Lost your Outlook Password? Crack it down using Outlook Recovery! Outlook Recovery is a password recovery tool (password cracker) for MS Outlook. It r...
Explorer View Outlook File Previewer
File previewer for Outlook. Instantly and safely preview almost any Microsoft Outlook attachments in the Outlook reading pane without leaving Outlook....
Outlook Date Stamper
Date Stamper for Microsoft Outlook is one-button add-in inserts current date and time into Outlook Contacts, Tasks, Emails, Appointments and other Out...
