Microsoft Outlook Express May Disclose 'bcc:' Recipient Addresses
|
|
SecurityTracker Alert ID: 1011067
|
|
SecurityTracker URL: http://securitytracker.com/id?1011067
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
|
OSVDB Reference: 9167
(Links to External Site)
|
Updated: Aug 27 2004
|
Original Entry Date: Aug 26 2004
|
Impact: Disclosure of user information
|
Fix Available: Yes
Exploit Included: Yes
Vendor Confirmed: Yes
|
Version(s): 6.0
|
Description: A vulnerability was reported in Microsoft Outlook Express. When large, multipart messages are sent, 'bcc:' recipient addresses may be disclosed to the other recipients.
Juha-Matti Laurio reported that when a target user sends a large e-mail when Microsoft Outlook Express is configured to break apart
e-mail messages of that size, any recipient addresses in the 'bcc:' field will be disclosed to the other recipients in the 'to:'
and 'cc:' fields.
|
Impact: A remote user that receives a message may be able to view any 'bcc:' addresses associated with that message.
|
Solution: A hotfix is available from Microsoft Product Support Services:
http://support.microsoft.com/default.aspx?scid=kb;EN-US;843555
|
Vendor URL: support.microsoft.com/default.aspx?scid=kb;EN-US;843555 (Links to External Site)
|
Cause: Access control error
|
Underlying OS: Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Aug 25, 2004
Subject: Microsoft Knowledge Base Article - 843555
|
http://support.microsoft.com/default.aspx?scid=kb;EN-US;843555
> E-mail recipients who are listed in the BCC box can be viewed by e-mail recipients
> who are listed in the To and CC boxes when you send a multi-part e-mail message by
> using Outlook Express 6.0
It is reported that when a target user sends a large e-mail when Microsoft Outlook
Express is configured to break apart e-mail messages of that size, any recipient
addresses in the 'bcc:' field will be disclosed to the other recipients in the 'to:'
and 'cc:' fields.
A hotfix is available from Microsoft Product Support Services:
http://support.microsoft.com/default.aspx?scid=fh;[LN];CNTACTMS
|
|