A bug in the HTML parser in a certain Microsoft HTML library, as used in various third party products, may allow remote attackers to cause a denial of service via certain strings, as reported in GFI MailEssentials for Exchange 9 and 10, and GFI MailSecurity for Exchange 8, which causes emails to remain in IIS or Exchange mail queues.
References
Link | Resource |
---|---|
http://www.csis.dk/default.asp?m=1&a=194 | Vendor Advisory |
http://kbase.gfi.com/showarticle.asp?id=KBID002249 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/12148 | |
http://secunia.com/advisories/13708 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-01-02 21:00
Updated : 2008-09-05 13:40
NVD link : CVE-2004-1312
Mitre link : CVE-2004-1312
JSON object : View
CWE
Products Affected
gfi
- mailsecurity
- mailessentials