exploits , vulnerabilities , articles , Microsoft Crypto API X.509 Certificate Validation Remote Information Disclosure Vulnerability
| Title |
Microsoft Crypto API X.509 Certificate Validation Remote Information Disclosure Vulnerability |
| Published |
2008-04-01-12:00AM |
| Updated |
2008-07-04-07:00PM |
| Class |
Design Error |
| CVE |
|
| Remote |
Yes |
| Local |
No |
| Credit |
Alexander Klink |
| Vulnerable |
Microsoft Windows Live Mail 2008 0 Microsoft Outlook 2007 0 Microsoft Office 2007 SP1 Microsoft Office 2007 0 Microsoft Access 2007 0 Microsoft Access 2007 0 Microsoft Excel 2003 Microsoft Excel 2007 0 Microsoft Excel 2007 0 Microsoft FrontPage 2003 Microsoft Groove 2007 0 Microsoft Groove 2007 0 Microsoft InfoPath 2003 Microsoft InfoPath 2007 0 Microsoft InfoPath 2007 0 Microsoft Office Communicator 2007 0 Microsoft Office Communicator 2007 0 Microsoft OneNote 2003 0 Microsoft Outlook 2003 0 Microsoft Outlook 2007 0 Microsoft Outlook 2007 0 Microsoft PowerPoint 2003 0 Microsoft PowerPoint 2007 0 Microsoft PowerPoint 2007 0 Microsoft Project Professional 2007 0 Microsoft Project Professional 2007 0 Microsoft Project Standard 2007 0 Microsoft Project Standard 2007 0 Microsoft Publisher 2003 Microsoft Publisher 2007 0 Microsoft Publisher 2007 0 Microsoft SharePoint Designer 2007 0 Microsoft SharePoint Designer 2007 0 Microsoft Visio Professional 2007 0 Microsoft Visio Professional 2007 0 Microsoft Visio Standard 2007 0 Microsoft Visio Standard 2007 0 Microsoft Crypto API 0
|
| Not Vulnerable |
|
| Code |
The following Office document will trigger HTTP requests to an external webserver.The referenced advisories also state that sending a blank email to <smime-http@klink.name> will result in a reply email that is S/MIME-encoded in a manner that also triggers the issue.Symantec has not validated the safety of the document or email, so users should take appropriate precautions for handling potentially malicious content. /data/vulnerabilities/exploits/HTTP_over_Office_2007_PoC.docx |
| TXT |
 |
|
Advertising
|
|
Copyright 2007,
SecurityDot
Sat, 22 Nov 2008 22:58:09 +0000
Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS
EXPLOITS
VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
i.../31377 xxxpechtv. free photo t298t pinchunter Bokp indo sex maroc. 10.20.30.t www.geteen /board/kbo 2.6.9-023 sex girls .asp tokyosex www.pornor Animail se P...Foptio www.youtob phphtml.ph ms06-077 dwl-g132 200+/compo Www.17 ABG bdir.htr carlcomms wwwporno.c Www.my+sex Foto bugil Fedora 5 www.zoopor sseyx MEN film sexs Linux Kern Ww.indian botnet mambo Remo master.pas for sania CMS is Fre t174t singer imtoo 3gp sex girls Hindi movi www. iranx Www+xxx+na gaypics DRESS Buffer Ove
|