[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244411

 
 

909

 
 

193363

 
 

277

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-3068Date: (C)2008-07-07   (M)2023-12-22


Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1019736
SECTRACK-1019737
SECTRACK-1019738
http://www.securityfocus.com/archive/1/493947/100/0/threaded
http://www.securityfocus.com/archive/1/494101/100/0/threaded
BID-28548
SREASON-3978
https://www.cynops.de/advisories/AKLINK-SA-2008-002.txt
https://www.cynops.de/advisories/AKLINK-SA-2008-003.txt
https://www.cynops.de/advisories/AKLINK-SA-2008-004.txt
https://www.cynops.de/techzone/http_over_x509.html
https://www.klink.name/security/aklink-sa-2008-002-outlook-smime.txt
https://www.klink.name/security/aklink-sa-2008-003-live-mail-smime.txt
https://www.klink.name/security/aklink-sa-2008-004-office2007-signatures.txt

CPE    18
cpe:/a:microsoft:onenote:2003
cpe:/a:microsoft:sharepoint_designer:2007
cpe:/a:microsoft:powerpoint:2003
cpe:/a:microsoft:frontpage:2003
...

© SecPod Technologies