漏洞信息详情
Microsoft Outlook/Exchange TNEF解码远程代码执行漏洞
漏洞简介
Microsoft Outlook和Exchange都是微软发布的邮件处理软件。
Microsoft Outlook和Microsoft Exchange Server解码传输中立封装格式(TNEF)MIME附件的方式存在漏洞,攻击者可能利用此漏洞在机器上执行任意指令。攻击者可以创建特制的TNEF消息,如果用户打开或浏览了恶意的邮件消息或Microsoft Exchange Server Information Store处理了该特制消息的话,就可能执行任意代码。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接
http://www.microsoft.com/technet/security/Bulletin/MS06-003.mspx
参考网址
来源:SECTRACK
链接:http://securitytracker.com/id?1015461
来源:OVAL
链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1485
来源:SECTRACK
链接:http://securitytracker.com/id?1015460
来源:BUGTRAQ
链接:http://www.securityfocus.com/archive/1/421520/100/0/threaded
来源:CERT-VN
链接:http://www.kb.cert.org/vuls/id/252146
来源:OVAL
链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1456
来源:SECUNIA
链接:http://secunia.com/advisories/18368
来源:SREASON
链接:http://securityreason.com/securityalert/330
来源:OVAL
链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1316
来源:OVAL
链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A624
来源:SREASON
链接:http://securityreason.com/securityalert/331
来源:MS
链接:https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-003
来源:BUGTRAQ
链接:http://www.securityfocus.com/archive/1/421518/100/0/threaded
来源:CONFIRM
链接:http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm
来源:VUPEN
链接:http://www.vupen.com/english/advisories/2006/0119
来源:OVAL
链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1082
来源:BID
链接:https://www.securityfocus.com/bid/16197
来源:CERT
链接:http://www.us-cert.gov/cas/techalerts/TA06-010A.html
来源:XF
链接:https://exchange.xforce.ibmcloud.com/vulnerabilities/22878
来源:OVAL
链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1165
受影响实体
- Microsoft Exchange_server:5.0<!--2000-1-1-->
- Microsoft Exchange_server:5.0:Sp1<!--2000-1-1-->
- Microsoft Outlook:2003<!--2000-1-1-->
- Microsoft Office:2000:Sp3<!--2000-1-1-->
- Microsoft Outlook:2000:Sp3<!--2000-1-1-->
补丁
- Microsoft Outlook/Exchange TNEF解码远程代码执行漏洞 的修复措施<!--2006-1-10-->
还没有评论,来说两句吧...