Vulnerability Name: | CVE-2002-0285 (CCN-8198) | ||||||||
Assigned: | 2002-02-12 | ||||||||
Published: | 2002-02-12 | ||||||||
Updated: | 2016-10-18 | ||||||||
Summary: | Outlook Express 5.5 and 6.0 on Windows treats a carriage return ("CR") in a message header as if it were a valid carriage return/line feed combination (CR/LF), which could allow remote attackers to bypass virus protection and or other filtering mechanisms via a mail message with headers that only contain the CR, which causes Outlook to create separate headers. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Tue Feb 12 2002 - 15:06:29 CST Outlook will see non-existing attachments Source: MITRE Type: CNA CVE-2002-0285 Source: BUGTRAQ Type: UNKNOWN 20020212 Outlook will see non-existing attachments Source: XF Type: UNKNOWN outlook-express-return-bypass(8198) Source: CCN Type: OSVDB ID: 11419 Microsoft Outlook Express Header Carriage Return Filter Bypass Source: BID Type: UNKNOWN 4092 Source: CCN Type: BID-4092 Outlook Express Attachment Carriage Return/Linefeed Encapsulation Filtering Bypass Vulnerability Source: XF Type: UNKNOWN outlook-express-return-bypass(8198) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |