PureBytes Links
Trading Reference Links
|
--- Begin Message ---
To: swp <swp@xxxxxxxxxx>
Subject: Re: [Fwd: question regarding email vulnerability]
From: CIAC <ciac@xxxxxxxx>
Date: Thu, 5 Nov 1998 13:10:23 -0800 (PST)
CC: CIAC <ciac@xxxxxxxx>
In-Reply-To: <364060F5.D84@xxxxxxxxxx>
-----BEGIN PGP SIGNED MESSAGE-----
Hi Steven,
I wanted to follow up on the message Rose sent you that
we haven't seen a system infected by the way you
described.
Over the summer there was a lot of attention given to
a MIME Buffer Overflow problem in Netscape and
Internet Explorer and Microsoft's Outlook programs.
This problem could allow an attachment to automatically
open and run thus infecting your system. We haven't
seen this happen to any of our users but it could!
The best thing you can do is get the latest patches and
upgrades to any of the programs I mentioned above. If
you are not using any of those products you should
be safe...that is until someone discovers something
else. I use to tell folks you could never get infected
by a virus as long as you don't click on or launch an
attachment but since I've started working with CIAC
I've learned to never say never anymore! ;-)
Hope this helps. CIAC does have a bulletin you can
read that talks a little more about this problem on
our web site.
http://ciac.llnl.gov/ciac/bulletins/i-077b.shtml
You might also want to check out our bulletin on
the Eudora e-mail program. It had a problem that
wasn't related to MIME but by hiding a attachment
within an URL. This could also launch a attachment
unexpectedly.
http://ciac.llnl.gov/ciac/bulletins/i-083.shtml
Take care,
Greg Roll
- - -----------------------------------------------------------------
Computer Incident Advisory Capability (CIAC) Greg Roll
(925)422-8193 (925)423-9089
ciac@xxxxxxxx roll1@xxxxxxxx
- - ------------------------------------------------------------------
> Is is possible to get infected with a virus just by opening an email
> without clicking on an attachment or URL. That is, is there a way
that a
> program could execute just by opening an email message in your
mailbox
> via a java script or something like that?
>
> Steven Poser
>
>
> </BLOCKQUOTE>
> <P><EM>-- END included message</EM></P>
>
-----BEGIN PGP SIGNATURE-----
Version: PGP for Business Security 5.5.2
iQCVAwUBNkIVWrnzJzdsy3QZAQHcFQP9E0K9La6P0SSBHI+l9kMYffxo4oAJZtwK
+BDAViBF+lOw/cFtt1kdiCzb/lgbwisk+xGGtBn0BQaL0VB8CxrNDMOVieJpoK1D
gj3JEJC4/Y1IdcEY6AIcCW5spIK2mf9M48LdhltAzbvw2A7ZeplCwr6bjIcRXpqm
85RG5s6ayww=
=Hx6+
-----END PGP SIGNATURE-----
--- End Message ---
|