CVE Vulnerabilities

CVE-2001-1088

Published: Jun 05, 2001 | Modified: Oct 10, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the Automatically put people I reply to in my address book option enabled, do not notify the user when the Reply-To address is different than the From address, which could allow an untrusted remote attacker to spoof legitimate addresses and intercept email from the client that is intended for another user.

Affected Software

Name Vendor Start Version End Version
Outlook Microsoft 97 97
Outlook Microsoft 98 98
Outlook Microsoft 2000 2000
Outlook_express Microsoft 4.0 4.0
Outlook_express Microsoft 4.5 4.5
Outlook_express Microsoft 4.27.3110 4.27.3110
Outlook_express Microsoft 4.72.2106 4.72.2106
Outlook_express Microsoft 4.72.3120.0 4.72.3120.0
Outlook_express Microsoft 4.72.3612 4.72.3612
Outlook_express Microsoft 5.0 5.0
Outlook_express Microsoft 5.5 5.5

References