CERTA-2001-AVI-059
Vulnerability from certfr_avis
La manipulation de pièces jointes par le service OWA (Outlook Web Access) d'Exchange 2000 peut provoquer l'exécution de code arbitraire.
Description
OWA est un service d'Exchange 2000 Server qui permet à un utilisateur de se servir son navigateur pour accéder à sa boîte aux lettres Exchange.
Lors de la manipulation des pièces jointes, il existe un problème d'interaction entre OWA et Internet Explorer. En effet, si une pièce jointe contient du code HTML incluant un script, ce script sera exécuté lors de l'ouverture de la pièce jointe.
Contournement provisoire
Ne pas utiliser Internet Explorer avec OWA, mais se servir d'un autre navigateur.
Solution
Appliquer le correctif Microsoft :
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=30436
Exchange 2000.
Impacted products
| Vendor | Product | Description |
|---|
References
| Title | Publication Time | Tags | |||
|---|---|---|---|---|---|
|
|||||
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [],
"affected_systems_content": "\u003cP\u003eExchange 2000.\u003c/P\u003e",
"content": "## Description\n\nOWA est un service d\u0027Exchange 2000 Server qui permet \u00e0 un utilisateur de\nse servir son navigateur pour acc\u00e9der \u00e0 sa bo\u00eete aux lettres Exchange. \n\nLors de la manipulation des pi\u00e8ces jointes, il existe un probl\u00e8me\nd\u0027interaction entre OWA et Internet Explorer. En effet, si une pi\u00e8ce\njointe contient du code HTML incluant un script, ce script sera ex\u00e9cut\u00e9\nlors de l\u0027ouverture de la pi\u00e8ce jointe.\n\n## Contournement provisoire\n\nNe pas utiliser Internet Explorer avec OWA, mais se servir d\u0027un autre\nnavigateur.\n\n## Solution\n\nAppliquer le correctif Microsoft :\n\n http://www.microsoft.com/Downloads/Release.asp?ReleaseID=30436\n",
"cves": [],
"initial_release_date": "2001-06-07T00:00:00",
"last_revision_date": "2001-06-07T00:00:00",
"links": [],
"reference": "CERTA-2001-AVI-059",
"revisions": [
{
"description": "version initiale.",
"revision_date": "2001-06-07T00:00:00.000000"
}
],
"risks": [
{
"description": "Ex\u00e9cution de code arbitraire"
}
],
"summary": "La manipulation de pi\u00e8ces jointes par le service OWA (Outlook Web\nAccess) d\u0027Exchange 2000 peut provoquer l\u0027ex\u00e9cution de code arbitraire.\n",
"title": "Vuln\u00e9rabilit\u00e9 d\u0027Exchange 2000",
"vendor_advisories": [
{
"published_at": null,
"title": "Bulletin de s\u00e9curit\u00e9 Microsoft",
"url": "http://www.microsoft.com/technet/security/bulletin/ms01-030.asp"
}
]
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…