Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2005-1987

Description

Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.

POC

Reference

- http://marc.info/?l=bugtraq&m=112915118302012&w=2

- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-048

Github

- https://github.com/ARPSyndicate/cve-scores