Full Disclosure mailing list archives

Outlook Express Remote Code Execution in Preview Pane (S/MIME)


From: nexus () patrol i-way co uk (Nexus)
Date: Fri, 11 Oct 2002 01:51:19 +0100

----- Original Message -----
From: "HggdH" <hggdh () attbi com>
To: <full-disclosure () lists netsys com>
Sent: Friday, October 11, 2002 12:41 AM
Subject: Fw: [Full-disclosure] Outlook Express Remote Code Execution in
Preview Pane (S/MIME)


I went ahead, and downloaded and applied the patch to one of my systems..

This system is a Windows 2000 SP3 + all sec patches to dsate,  IE6 SP1
V6.0.2800.1106, OE6 V6.0.2800.1106.

To my surprise, the patch refused to install, telling me "This update
requires Internet Explorer 6.0 to be installed.".

So. Is Outlook Express V6 (as of MS Internet Explorer V6 SP1) vulnerable
or
not?

See below.

Cheers.


----- Original Message -----
From: "Russ" <Russ.Cooper () RC ON CA>
To: <NTBUGTRAQ () LISTSERV NTBUGTRAQ COM>
Sent: Friday, October 11, 2002 1:33 AM
Subject: Re: Problems applying MS02-058


Several people reported the same problem with MS02-058;

"This update requires Internet Explorer 6.0 to be installed."

Seems that this is the error you'll get if you try to install that patch
on a system which already has the patched component installed. Seems that
this patch was already included in all of the following;

1. Internet Express 6.0 SP1
2. Outlook Express 6.0 SP1
3. Windows XP SP1

So, before you apply the patch double-check to see what you're already
running.

Cheers,
Russ - NTBugtraq Editor




Current thread: