OSVDB ID: 19905

Title: Microsoft Collaboration Data Objects Remote Overflow

Info

Disclosure

Oct 11, 2005

Discovery

Unknown

Dates

Exploit

Oct 13, 2005

Solution

Unknown

Description

A remote overflow exists in Microsoft Collaboration Data Objects (CDO). The component fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted email message containing an overly long header line, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Rumored
Disclosure: OSVDB Verified

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.

Products

Microsoft Corporation

Exchange Server

2000 SP3

Windows

XP SP2
2003 Server SP1
XP Pro x64
2003 Server SP1 for Itanium
2003 Server x64
2003 Server
XP SP1
2000 SP4
2003 Server for Itanium

References

Credit

  • Gary O'leary-Steele - GaryOsec-1.com - SEC-1 LTD


Direct URL: http://osvdb.org/19905