On TV.com: HANK Stank, Now It's Canceled
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Jul 11, 2002 6:45:00 PM

A widely used plug-in for Microsoft's Outlook e-mail client that lets users encrypt and digitally sign messages has inadvertently weakened security and left the mail program open to attack.


Outlook woes
New bug found in Outlook, IE


Security company eEye Digital Security issued a warning late Wednesday to users of Network Associates' Pretty Good Privacy (PGP) plug-in for Outlook, saying that a vulnerability in the add-on could let attackers execute malicious software on a victim's computer. Network Associates released a patch for the problem Wednesday as well.

The irony of the flaw--it affects the most security conscious of computer users--did not escape Marc Maiffret, chief hacking officer for eEye.

"PGP is such a trusted product," Maiffret said. "It's a product made specifically to stop attackers from accessing your data, and here it is not only not stopping them but making it easier to get in."

The flaw occurs because PGP handles certain malformed e-mails incorrectly, said the eEye advisory. An attacker could send a specially crafted e-mail to an Outlook user who has the PGP plug-in installed and could then be able to access that user's system. Not only could attackers execute hostile programs, they could also steal the victim's private encryption keys and have access to coded communications.

Although he expected PGP users to patch their systems quickly, Maiffret said the danger is somewhat magnified by the fact that not only the sender but also all the recipients of encrypted e-mail have to have patched their PGP plug-in.

"If the person you are sending stuff to has not applied the patch, then you are still at risk," Maiffret said.

Microsoft's Outlook e-mail client has been lambasted in the past for its poor security. This time, however, the problem is not with the program but with a plug-in.

The issue doesn't affect PGP Corporate Desktop users, stated Network Associates in its advisory. The patch is available on the company's Web site.

SponsoredWhite Papers, Webcasts, and Downloads

Talkback

Add your opinion
advertisement
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
Reduce risk. Reduce complexity. Increase reliability.
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
Learn more >>
Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.
Learn more about the free, six-month trial offer>>
The more you simplify, the more you save
When you transition from your existing Red Hat environment to SUSE Linux Enterprise from Novell, you can recognize dramatic cost savings, perhaps as much 50%
Learn more >>
The best support in the Linux business
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
Learn more >>
Keep Up With The Latest In Document Management with The DocuMentor.
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
Learn more >>
Learn more about tools to grow your business
The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
Save time with the UPS Business Essentials Guide
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here