CVE-1999-1016: Medium severity Microsoft Outlook Express vulnerability
Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable rendering of HTML email (view messages as plain text) to avoid processing HTML form fields that can cause a denial of service.
Microsoft Outlook Express render_html_email = disable - Compensating control
Filter or block malicious HTML content at the network/perimeter (web proxy, firewall, or SMTP/HTTP gateway). Restrict or block access to untrusted web sites and block delivery of HTML emails from untrusted sources to prevent exposure to the vulnerable HTML control.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1016?
CVE-1999-1016 is classified as a denial of service vulnerability due to its potential to cause 100% CPU consumption.
How do I fix CVE-1999-1016?
To mitigate CVE-1999-1016, it is recommended to update to the latest versions of affected software, which are no longer supported, or consider alternative software solutions.
Which software is affected by CVE-1999-1016?
CVE-1999-1016 affects Microsoft Internet Explorer 5.0, FrontPage Express, Outlook Express 5, and Qualcomm Eudora.
What are the implications of CVE-1999-1016?
The implications of CVE-1999-1016 include potential disruption of service and system performance degradation due to excessive CPU usage.
Can CVE-1999-1016 be exploited through email?
Yes, CVE-1999-1016 can be exploited through malicious HTML emails that utilize large HTML form fields.