Report
This patch (KB897715) applies to Outlook Express 6.0 SP1: you must have
already installed Internet Explorer 6 Service Pack 1 before this patch
(IE6 SP1 includes Outlook Express 6 SP1 - that is why you need to install
IE6 SP1 first). The update can be applied to any previously patched
release (some of the changes below may already be made to your system
if it has been patched with earlier updates). And finally, Microsoft
now differentiate between the version of Outlook Express that was included
with Windows XP SP2 compared to Outlook Express 6 SP1 on Windows SP1
or Windows 2000 PCs. In other words, if you have Windows 2000 or XP
without SP2, download this file. If you do have XP with SP2 installed,
you will need to download a different file (click the Windows button
in the left menu for files you will need).
Changes
in this update
Windows Address Book Contact Record Vulnerability
Outlook Express News Reading Vulnerability
Another big oops from Microsoft - sometimes a message header may contain
recipients that were included in the BCC (Blind Carbon Copy) field of
the message. This is now fixed.
When you receive an Outlook Express e-mail message that was sent by
using a Japanese version of Microsoft Windows XP, the name that is displayed
in the From field may not appear correctly
Fixes a security hole that may allow a hacker to crash Outlook Express
The ability to differentiate between sending a message and posting to
a newsgroup
Added 'View replies' toggle
Fixes the following issues:
MHTML URL Processing Vulnerability that allows Remote Code Execution
Outlook Express quits unexpectedly when you receive a message that has
a special MIME header (321530)
Japanese character is not displayed correctly when you use MAPIReadMail
(317011)
An access violation (fatal exception error or 'msimn.exe has performed
an illegal operation') occurs in Outlook Express if you click cancel
when you are choosing a message store (312590).
The cumulative update for Outlook Express 6.0 SP-1 contains high-level
security fixes, which fixed or removed all bounded and unbounded string
functions.
Other fixes:
You
can now delete individual newsgroup messages from the local .dbx (Filestorage)
Outlook Express will now save an attachment to the default path
When you use long URLs in the body of a message, the URL will no longer
break if it wraps. This also is fixed when the URL contains two dashes
followed by a space.
Outlook Express will stop hanging when you click Signature on the Insert
menu to add a signature to a message.