Full Disclosure mailing list archives

Microsoft Outlook Vulnerability: S/MIME Loss of Integrity


From: Defence in Depth <defenceindepth () gmail com>
Date: Sun, 16 Jun 2013 00:51:10 +0930

** Attention script bunnies: This is not an RCE, XSS, etc. Please move
along :) **

Microsoft Outlook (all versions) suffers from an S/MIME loss of integrity
issue.
Outlook does not warn against a digitally signed MIME message whose X509
EmailAddress attribute does not match the mail's "From" address.

Full details:
http://www.defenceindepth.net/2013/06/smime-bucking-phishing-trend.html
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: