OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Remote DoS in GFI MailEssentials due to a bug in Microsoft HTML parser

From: Bill Royds (billROYDS.NET)
Date: Wed Jan 12 2005 - 10:21:23 CST


Microsoft Outlook 2003 with McAfee VirusScan is also sometimes susceptible to
this vulnerability, depending on the virus found. Files infected by dumaru are
most often prone to it.
Because Outlook 2003 can download only headers of a message (download Inbox
headers under Send/Receive), you can then delete them without loading whole
message, clearing the queue.

-----Original Message-----
From: Windows NTBugtraq Mailing List [mailto:NTBUGTRAQLISTSERV.NTBUGTRAQ.COM]
On Behalf Of Peter Kruse
Sent: Monday, January 03, 2005 7:50 AM
To: NTBUGTRAQLISTSERV.NTBUGTRAQ.COM
Subject: Remote DoS in GFI MailEssentials due to a bug in Microsoft HTML parser

--
NTBugtraq Editor's Note:

Most viruses these days use spoofed email addresses. As such, using an Anti-Virus product which automatically notifies the perceived sender of a message it believes is infected may well cause more harm than good. Someone who did not actually send you a virus may receive the notification and scramble their support staff to find an infection which never existed in the first place. Suggest such notifications be disabled by whomever is responsible for your AV, or at least that the idea is considered.
--