[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Fwd: Special Alert - E-mail security issue]



PureBytes Links

Trading Reference Links

Since this list has shown a fair amount of interest in internet
security issues, I thought I would forward the attached message
from Microsoft. 

Netscape has acknowledged a similar problem and is working on a
solution.  See the URL:

http://search.netscape.com/products/security/resources/bugs/longfile.html

Just in case, note that as I write this the last letter of the 
URL wrapped to the next line.

RodReceived: from bulk-03-imc.newswire.microsoft.com (bulk-03-imc.newswire.microsoft.com [131.107.38.12]) by mailbox.neosoft.com (8.8.8/8.8.8) with ESMTP id CAA28756 for <grisham@xxxxxxxxxxx>; Thu, 6 Aug 1998 02:35:11 -0500 (CDT)
Message-Id: <199808060735.CAA28756@xxxxxxxxxxxxxxxxxxx>
Received: from PickupDirectory by bulk-03-imc.newswire.microsoft.com with SMTP (Microsoft Exchange Internet Mail Service Version 5.5.2166.0)
	id PYJBDYW1; Thu, 6 Aug 1998 00:34:37 -0700
From: "Microsoft" <Microsoft_001321@xxxxxxxxxxxxxxxxxxxxxxxxxxx>
To: <grisham@xxxxxxxxxxx>
Subject: Special Alert - E-mail security issue
Date: Wed, 5 Aug 1998 20:36:17 -0700
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
X-MimeOLE: Produced By Microsoft MimeOLE V4.72.2106.4


This is a special alert message to registered users of Microsoft Office, Microsoft Outlook 98, Microsoft Internet Explorer version 4.0 or later, and Microsoft Windows 98.  We want to inform you of a security issue that affects e-mail packages including Microsoft Outlook 98 and Microsoft Outlook Express versions 4.0 or later.  Microsoft has created a fix for this security issue, which can be downloaded from
http://www.microsoft.com/security/

This security issue involves how e-mail software handles file attachments with extremely long file names.  When users attempt to download, open or launch a file attachment that has a name containing more than a certain number of characters, their action can cause the program to shut down unexpectedly.  It is possible - although difficult - for a hacker to cause malicious code to be executed on a computer as a result of this problem. However, this cannot be caused accidentally, and to date we have received no reports of users being affected.  More information on this issue can be found at
http://www.microsoft.com/security/bulletins/ms98-008.htm

Microsoft takes security very seriously, and we know you do as well.  Microsoft is committed to ensuring that all its customers enjoy a rich, safe and secure computing experience and developers have been working around the clock to isolate and deal with these issues.  Microsoft has provided software patches for both Outlook Express and Outlook 98 at
http://www.microsoft.com/security/
We strongly recommend that you download the appropriate patch immediately.

To ensure customer safety with regard to this and other security-related issues, Microsoft is investigating further to uncover variants that the current patch may not block. Microsoft will communicate additional information about this research as it becomes available.  You can also visit
http://www.microsoft.com/security/.
for the latest information and updates, and to register for the Microsoft Security Notification Service.

Thank you.



=====================================================================
Microsoft, Outlook, and Windows are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries.  Other product and company names mentioned herein may be the trademarks of their respective owners.

~~~~~~~~~~~~~~~~~~~~~~~~
How to use this mailing list:
~~~~~~~~~~~~~~~~~~~~~~~~
Our relationship with you is very important to us.  If you do not want to receive e-mail from Microsoft.com's e-mail service, please visit our Web site at:
http://www.microsoft.com/misc/unsubscribe.htm

This is the place you can subscribe or unsubscribe to our free e-mail newsletters and/or choose not to receive e-mail from Microsoft.com's e-mail service.

Alternatively, please send a reply to this e-mail with the word "unsubscribe" as the first line in the body of the message.

~~~~~~~~~~~~~~~~~~~~~~~~
THIS DOCUMENT IS PROVIDED FOR INFORMATIONAL PURPOSES ONLY.  The information contained in this document represents the current view of Microsoft Corporation on the issues discussed as of the date of publication.  Because Microsoft must respond to change in market conditions, it should not be interpreted to be a commitment on the part of Microsoft and Microsoft cannot guarantee the accuracy of any information presented after the date of publication.
INFORMATION PROVIDED IN THIS DOCUMENT IS PROVIDED 'AS IS' WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND FREEDOM FROM INFRINGEMENT.
The user assumes the entire risk as to the accuracy and the use of this document. This  document may be copied and distributed subject to the following conditions:
1.   All text must be copied without modification and all pages must be included
2.   All copies must contain Microsoft's copyright notice and any other notices provided therein
3.   This document may not be distributed for profit.