PT-2015-4935 · Al · Al-Mail32

Yosuka Hasegawa

·

Publicado

2015-02-20

·

Atualizado

2015-02-20

·

CVE-2015-0879

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions AL-Mail32 versions prior to 1.13d
Description The issue allows remote attackers to cause a denial of service, resulting in an application crash. This can be achieved by including specific device names in the filename of an attachment, such as CON, AUX, or NUL.
Recommendations For versions prior to 1.13d, update to version 1.13d or later to resolve the issue. As a temporary workaround, consider restricting the types of filenames that can be used for attachments to prevent the inclusion of device names like CON, AUX, or NUL.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-0879

Produtos afetados

Al-Mail32