Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

POP3:OUTLOOK:MULTIPLE-FROM

Severity

Low

Recommended

No

Category

POP3

Keywords

Outlook Address Spoofing

Release Date

2005/04/22

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

POP3: Outlook Address Spoofing


This signature detects multiple e-mail addresses in the FROM field of an e-mail message. Because Microsoft Outlook and Outlook Express display only the first e-mail address in the list, attackers can spoof the FROM e-mail address reported to the user.

Extended Description

Microsoft Outlook and Outlook Web Access clients are reported prone to a weakness that may allow remote attackers to send email with a spoofed address. It is reported that this issue arises when an attacker sends an e-mail by specifying multiple source email addresses. This issue may allow an attacker to carry out other attacks by combining this issue with social engineering and phishing attacks. An attacker may also bypass email gateways and send email to users.

Affected Products

  • Microsoft Exchange Server 2003
  • Microsoft Outlook 2003
  • Microsoft Outlook XP

References

  • BugTraq: 13078
  • CVE: CVE-2005-1052
  • URL: http://www.idefense.com/application/poi/display?id=227&type=vulnerabilities

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out