[28541] in bugtraq
certificate x.509 and outlook express 6
daemon@ATHENA.MIT.EDU (fabio miotti)
Tue Jan 21 23:13:40 2003
Date: 16 Jan 2003 13:38:09 -0000
Message-ID: <20030116133809.29892.qmail@www.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: fabio miotti <fabiotest80@libero.it>
To: bugtraq@securityfocus.com
In some cases Outlook Express shows a wrong certificate when i receive a
signed and encrypted message from another user.
Outlook Express uses the sender's certificate to encrypt the message, and
not the receipt's certificate!
Notwithstanding this, outlook express open the message, but this means the
sender's private key is seen by the receipt.