Short Name |
NNTP:OVERFLOW:OUTLOOK-NNTP-OF |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
NNTP |
Keywords |
Outlook Express NNTP Response Overflow |
Release Date |
2005/06/13 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability in the News reader functionality in Microsoft Outlook Express. Attackers can create a malicious News server that, when a user queries the server for news, enables the attacker to remotely execute code and/or completely control a target host.
Microsoft Outlook Express is prone to a buffer overflow when parsing NNTP responses. Successful exploits could allow arbitrary code to run in the context of the user running the application.