CVE Vulnerabilities

CVE-2007-0039

NULL Pointer Dereference

Published: May 08, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remote attackers to cause a denial of service (crash) via an Internet Calendar (iCal) file containing multiple X-MICROSOFT-CDO-MODPROPS (MODPROPS) properties in which the second MODPROPS is longer than the first, which triggers a NULL pointer dereference and an unhandled exception.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
Exchange_serverMicrosoft2000-sp3 (including)2000-sp3 (including)
Exchange_serverMicrosoft2003-sp1 (including)2003-sp1 (including)
Exchange_serverMicrosoft2003-sp2 (including)2003-sp2 (including)
Exchange_serverMicrosoft2007 (including)2007 (including)

Potential Mitigations

References