RE: Admin.dll (strings ./Admin.dll)

From: Isherwood Jeff C Contr AFRL/IFOSS (Jeffrey.Isherwoodat_private)
Date: Tue Sep 18 2001 - 15:17:20 PDT

  • Next message: JKruser: "RE: New Worm"

    We have al Java in email (outlook) disabled, but when we open the emails (or
    even preview them) they automaticaly launch (and of course try default media
    player for wav files cause of the associateion to wav-x).
    
    What I can't figure out is how is that java directed auto launch causing the
    attachment to automaticlly launch?  I've double & triple checked my test
    platform, Java scripting is disabled.
    
    
    -----Original Message-----
    From: Robert D. [mailto:xkillat_private]
    Sent: Tuesday, September 18, 2001 3:51 PM
    To: w1re p4ir
    Cc: incidentsat_private; vuln-devat_private
    Subject: Re: Admin.dll (strings ./Admin.dll)
    
    
    > Here's where it inserts the javascript to open the evil readme.eml mime
    Buffer overflow.
    
    I'm I correct assuming this is the same problem discussed in MS00-043?
    
    In that case the following configurations are safe:
    
    IE 5.01 SP1 or later
    IE 5.5 or later ( except Windows 2000, sp1 safe?? )
    



    This archive was generated by hypermail 2b30 : Tue Sep 18 2001 - 17:01:00 PDT