- Quick specs
- Price: Free
- Operating system: Windows 95, Windows NT, Windows XP, Windows 2000, Windows 98
- Date added: July 24, 2000
- Total Downloads: 15,469
- Downloads last week: 1
- See full specifications
- Average user rating: stars out of 26 votes
See all user reviews
Publisher's description
From Microsoft :A component shared by Outlook and Outlook Express, Inetcomm.dll, contains an unchecked buffer in the functionality that parses e-mail headers when downloading mail via either POP3 or IMAP4. By sending an e-mail that overruns the buffer, a malicious user could cause either of two effects to occur when the mail is downloaded from the server by an affected e-mail client: if the affected field is filled with random data, the e-mail could be made to crash; if the affected field is filled with carefully crafted data, the e-mail client could be made to run code of the malicious user's choice. The vulnerability affects all Outlook Express users and all Outlook users whose mail clients are configured to use either POP3 or IMAP4. Outlook users who have configured Outlook to use only MAPI services are unlikely to be affected by the vulnerability. Despite this, Microsoft recommends that such customers apply one of the corrective steps discussed in the Patch Availability section, primarily because the patch protects against other vulnerabilities that affect all Outlook users, regardless of the mail protocol they use.
A version of Inetcomm.dll that is not affected by the vulnerability ships as part of Outlook Express 5.5, and customers who have installed it do not need to take any additional action. Outlook Express 5.5 is available as part of Internet Explorer 5.01 Service Pack 1, and, except when installed on Windows 2000, Internet Explorer 5.5. Customers who do not wish to upgrade to Outlook Express 5.5 should install the patch.
More popular Encryption Software downloads
- 37,323 downloads 1. Computer Use Reporter
- 29,522 downloads 2. Hotspot Shield
- 26,293 downloads 3. RoboForm
- 10,828 downloads 4. Easy File Encryption
- 9,368 downloads 5. Easy Private Disk
- See all Encryption Software downloads
User reviews
- Average user rating: 0 stars Not yet available
- My rating: 0 stars Write review
-
Showing 3 of 3 user reviewsSee all 3 user reviews
This software version | All versions -
Version: Outlook Malformed E-mail Header Vulnerability Patch
Summary: It's programmed by microsoft. The programmed outlook express. They have some of the best programmers in the world.
I'm sure they are capable of fixing their own bugs. They would get alot of bad media publicity if it was found that it didn't fi... read more >> -
Version: Outlook Malformed E-mail Header Vulnerability Patch
Summary: How can we tell if it actually fixed this problem? We can't.
-
Version: Outlook Malformed E-mail Header Vulnerability Patch
"HAVE HAD NO PROBLEMS AT ALL."
- See all 3 user reviews Write review
Submit your review
- See more CNET content tagged:
- IMAP4,
- Microsoft Outlook,
- Microsoft Outlook Express,
- malicious user,
- vulnerability

