Executive brief
A security vulnerability exists in several older email clients, including Microsoft Outlook and Solaris mailtool, regarding how they process email attachments. If a user receives a message containing an attachment with an extremely long filename, the email application may crash or allow a malicious actor to run unauthorized code on the computer. This could lead to service disruptions or a full compromise of the user's workstation. Patches were released by the respective vendors to address this issue.
Technical details
A buffer overflow vulnerability exists in the MIME parsing component of various email clients, most notably Microsoft Outlook 98, Outlook Express 4.x, and Solaris mailtool. The flaw is triggered when the application processes a file attachment with an excessively long filename. In Outlook 98, the crash can occur automatically during the message download process without user interaction, while in Outlook Express, it typically occurs when a user attempts to open or view the attachment. An attacker can exploit this by sending a specially crafted email, potentially leading to arbitrary code execution or a denial of service (application crash). Microsoft released patches for affected versions in 1998.
Affected products
- Microsoft Outlook 98 Windows 95, 98, NT 4.0
- Microsoft Outlook Express 4.x 4.0, 4.01, 4.01 SP1
- Solaris mailtool All versions prior to patch
Timeline
- 1997-12-16: disclosed: Initial disclosure date recorded in NVD
- 1998-07-27: advisory: Microsoft published initial security bulletin MS98-008
- 1998-08-11: patched: Microsoft released updated patches addressing variants of the vulnerability