COMMAND

    mailnews.dll

SYSTEMS AFFECTED

    Mail/News

PROBLEM

    Balog Pal found following.  This is probably highly outdated,  but
    maybe  there  are  around  people  using  an  old  mail reader for
    whatever reasons:

        mailnews.dll, version 4.70.1161, date Thursday, March 13, 1997 5:32:38 PM

    It implements  the predecessor  of Outlook  Express, in  that time
    called  "Internet  Mail  and  News".   It  has  no  exe, the shell
    directly executes this dll using clsid

        {89292102-4755-11cf-9DC2-00AA006C2B84}

    It's originally  installed with  the NT  system, and  then updated
    (or left  alone) in  service packs.   This DLL  has at  least  one
    unchecked  buffer,  that  is  loaded  with  the MSGID field of the
    incoming mail. If you get a mail message with long data  (probably
    over 260 bytes)  it will crash  right during the  download. If the
    message somehow got into the message base, it will crash when  you
    read the message, and then do something else.  Other fields of the
    mail header might be infested with the same problem.

SOLUTION

    Nothing yet.