First published: Thu Mar 18 2004(Updated: )
Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Explorer | =6.0-sp1 | |
Microsoft Outlook | =2003 | |
Microsoft Outlook | =2002-sp2 | |
Microsoft Outlook | =2002-sp1 | |
Microsoft Outlook | =2002 | |
Internet Explorer | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0284 is categorized as a denial of service vulnerability that can lead to significant CPU consumption.
To mitigate CVE-2004-0284, ensure the 'Do not save encrypted pages to disk' setting is enabled in Microsoft Internet Explorer, Outlook 2002, and Outlook 2003.
CVE-2004-0284 affects Microsoft Internet Explorer 6.0 and Microsoft Outlook 2002 and 2003.
Yes, CVE-2004-0284 can be exploited by sending specially crafted HTML emails containing null characters.
The denial of service in CVE-2004-0284 is caused by remote attackers sending web pages or email that trigger excessive CPU usage.