First published: Tue Jun 14 2005(Updated: )
Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Outlook Express | =6.0-sp1 | |
Microsoft Outlook Express | =5.5-sp2 | |
Microsoft Outlook Express | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1213 is classified as a high-severity vulnerability due to its potential to allow arbitrary code execution.
To fix CVE-2005-1213, users should upgrade to the latest version of Microsoft Outlook Express or apply any relevant patches provided by Microsoft.
CVE-2005-1213 affects Microsoft Outlook Express 5.5 SP2, 6.0, and 6.0 SP1 installed on Windows operating systems.
CVE-2005-1213 can be exploited by remote malicious NNTP servers sending specially crafted LIST responses to vulnerable Outlook Express clients.
While CVE-2005-1213 is an older vulnerability, systems that still utilize affected versions of Outlook Express may remain at risk if not updated.