Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Outlook Express flaw speeds hacking
CNET News.com ^ | October 11, 2002, 10:40 AM PT | Robert Lemos

Posted on 10/11/2002 11:31:02 AM PDT by Bush2000

Outlook Express flaw speeds hacking

By Robert Lemos
Staff Writer, CNET News.com
October 11, 2002, 10:40 AM PT

Microsoft warned Outlook Express users late Thursday that a software flaw could allow an online vandal to control their computers. A critical vulnerability in the e-mail reader could allow an attacker to send a specially formatted message that would crash the software and potentially take control of the recipient's computer.

The flaw occurs in how the software handles messages that include components using secure MIME (multipurpose Internet mail extensions), a standard that allows e-mail messages to contain encrypted data and digital signatures.

"Outlook Express ships with every Windows system, or rather as part of IE, so it's on every system. But unless it is configured to receive mail, you are not at risk," said Scott Culp, manager for Microsoft security response.

Microsoft Outlook Express 5.5 and 6.0 are both affected. Earlier versions of the software giant's default e-mail application may also carry the flaw, but Microsoft hasn't tested the applications because they are no longer supported. Microsoft Outlook, the giant's full-featured e-mail and workgroup software, is not affected, Culp said.

The advisory released on Thursday includes links to a patch for Outlook Express 5.5 users and Outlook Express 6 Gold users. Anyone who has already downloaded and installed the Internet Explorer 6 service pack or the Windows XP service pack announced on Sept. 9 already have the patch, Culp said.

"We moved heaven and earth to get this into service packs," he said. Microsoft has found that its software service packs are downloaded in greater numbers, so the company tries to push out all application fixes that it can into the semiannual patches. Millions of people downloaded the two service packs in the first week, he said.

Focusing on the service pack had the consequence of delaying a patch for the smaller number of people who use Outlook Express 5.5 and Outlook Express 6.0 Gold, which is the company's internal term for the latest Outlook Express without any service packs applied. While the flaw had been found in late August and Microsoft rushed a patch out for the service packs released on Sept. 9, it took another 30 days for the company to release patches for other users.

"In order to meet the delivery date, we had to focus fully on the service packs," Culp said. "We didn't even start on OE 5.5 until after that."

The company updated the advisory, its 58th this year, on Friday morning to explain an error message that appears on computers that have Internet Explorer 6 service pack 1 already installed if the user tries to install the new patch. Microsoft stated that the message--"This update requires Internet Explorer 6.0 to be installed"--is incorrect and should say that the patch is not needed.


TOPICS: Business/Economy; Politics/Elections; Technical
KEYWORDS: elections; exploit; lookoutexpress; lowqualitycrap; malware; microsoft; outlookexpress; politics; securityflaw; techindex; web; windows
This has already been fixed. If you use Outlook Express, get the patch here.
1 posted on 10/11/2002 11:31:02 AM PDT by Bush2000
[ Post Reply | Private Reply | View Replies]

To: Bush2000
I use Poco Mail for my email client. Simple, powerful, and avoids all those nasty Outlook viruses...
2 posted on 10/11/2002 12:04:33 PM PDT by egarvue
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bush2000
Bumping to keep that link.
3 posted on 10/11/2002 3:41:32 PM PDT by hchutch
[ Post Reply | Private Reply | To 1 | View Replies]

To: hchutch; Bush2000; *tech_index; Mathlete; Apple Pan Dowdy; grundle; beckett; billorites; ...
News here says there are install problems with the patch although I installed OK!

Microsoft Outlook Express Patch Flawed

OFFICIAL BUMP(TOPIC)LIST

4 posted on 10/11/2002 9:48:28 PM PDT by Ernest_at_the_Beach
[ Post Reply | Private Reply | To 3 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson