funsec mailing list archives

Re: 2 critical vulns and the clock is ticking..[Fwd: [EEYEB-2000801]]


From: Valdis.Kletnieks () vt edu
Date: Wed, 11 Jan 2006 00:34:52 -0500

On Tue, 10 Jan 2006 22:10:49 EST, "Richard M. Smith" said:
Thanks for the background.  Is there anyway to find out all the flavors of
MIME types that Outlook and Outlook Express will accept as email messages?

Probably not.  I suspect that LookOut! and friends will accepted almost
anything and try to display or execute it, even if it is a bad idea.

Hell, at one point, IE was perfectly willing to be handed a file called
'foo.jpg', and server typed as an image/jpeg, and *still* search the file
for Javascript to execute.  Gaak.

Attachment: _bin
Description:

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.

Current thread: