Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
| Software | From | Fixed in |
|---|---|---|
| microsoft / exchange_server | 5.5-sp1 | 5.5-sp1.x |
| microsoft / office | 2003-sp1 | 2003-sp1.x |
| microsoft / exchange_server | 5.5-sp4 | 5.5-sp4.x |
| microsoft / office | xp-sp3 | xp-sp3.x |
| microsoft / outlook | 2000-sp3 | 2000-sp3.x |
| microsoft / outlook | 2003 | 2003.x |
| microsoft / exchange_server | 5.5-sp2 | 5.5-sp2.x |
| microsoft / office | 2003-sp2 | 2003-sp2.x |
| microsoft / outlook | 2002-sp3 | 2002-sp3.x |
| microsoft / exchange_server | 2000-sp3 | 2000-sp3.x |
| microsoft / exchange_server | 5.5-sp3 | 5.5-sp3.x |
| microsoft / exchange_server | 5.0-sp1 | 5.0-sp1.x |
| microsoft / exchange_server | 5.0-sp2 | 5.0-sp2.x |
| microsoft / office | 2000-sp3 | 2000-sp3.x |
| microsoft / exchange_server | 5.5 | 5.5.x |
| microsoft / exchange_server | 5.0 | 5.0.x |