SMTP: Collaboration Data Objects Vulnerability

This signature detects the SMTP transmission of a maliciously crafted e-mail, designed to exploit a vulnerability in Microsoft IIS.

Extended Description

Microsoft CDO is susceptible to a remote buffer overflow vulnerability. This issue is due to a failure of the library to properly bounds check user-supplied data prior to copying it to an insufficiently sized memory buffer. This issue presents itself when an attacker sends a specifically crafted email message to an email server utilizing the affected library. This issue allows remote attackers to execute arbitrary machine code in the context of the application utilizing the library.

Affected Products

Microsoft windows_xp_media_center_edition

Short Name
SMTP:IIS:CDO-OF
Severity
Minor
Recommended
False
Recommended Action
None
Category
SMTP
Keywords
CVE-2004-0399 CVE-2005-1987 Collaboration Data Objects Vulnerability bid:15067
Release Date
10/11/2005
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

srx-branch-12.3

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx-12.3

vmx-19.3

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Nortel_networks

Microsoft

CVSS Score

7.5

Found a potential security threat?