PT-2006-1687 · Ritlabs · The Bat!
Published
2006-02-10
·
Updated
2018-10-19
·
CVE-2006-0630
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
The Bat! versions prior to 3.0.0.15
Description
The issue concerns the display of certain important headers from encapsulated data in message/partial MIME messages, instead of the real headers, violating RFC2046 header merging rules. This allows remote attackers to spoof the origin of e-mail by sending a fragmented message, potentially using spoofed
Received: and Message-ID: headers.Recommendations
For versions prior to 3.0.0.15, update to version 3.0.0.15 or later to resolve the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
The Bat!