COMMAND
mailnews.dll
SYSTEMS AFFECTED
Mail/News
PROBLEM
Balog Pal found following. This is probably highly outdated, but
maybe there are around people using an old mail reader for
whatever reasons:
mailnews.dll, version 4.70.1161, date Thursday, March 13, 1997 5:32:38 PM
It implements the predecessor of Outlook Express, in that time
called "Internet Mail and News". It has no exe, the shell
directly executes this dll using clsid
{89292102-4755-11cf-9DC2-00AA006C2B84}
It's originally installed with the NT system, and then updated
(or left alone) in service packs. This DLL has at least one
unchecked buffer, that is loaded with the MSGID field of the
incoming mail. If you get a mail message with long data (probably
over 260 bytes) it will crash right during the download. If the
message somehow got into the message base, it will crash when you
read the message, and then do something else. Other fields of the
mail header might be infested with the same problem.
SOLUTION
Nothing yet.