

DOVES Vulnerability V-00110
DOVES Project
Computer Security Laboratory
Department of Computer Science
University of California at Davis
Brief summary: A remote user could read email of another user
Detailed description: Microsoft's Outlook Express accepts mail with HTML commands and interprets the HTML. So, it can open a browser window that links back to the Outlook Express window. The browser can contain a script to read the HTML mail being displayed in Outlook Express. However, the link can be made persistent, in which case a script in the browser window could read all mail displayed in the preview pane of that session of Outlook Express. The browser could then relay contents of the mail elsewhere.
Components: Outlook Express 4.0, 4.01, 5.0, 5.01
Operating system(s): Windows NT 4.0, all versions; Windows 2000, all versionsThe attacker can view the user's email
How to detect:
How to fix:
Other information:
PA Classification:
RISOS Classification:
Davis Classification:
Attacks: See Doves exploit #108
Advisories:
Who reported it: Microsoft in Microsoft security bulletin on July 20, 2000: reported the problem
Send email to doves@cs.ucdavis.edu
Department of Computer Science
University of California at Davis
One Shields Ave.
Davis, CA 95616-8562
Dove images © 1999-2000 www.barrysclipart.com