Rit Research Labs The Bat! 1.53 - Microsoft Denial of Service Device Name Denial of Service

Author: 3APA3A
type: dos
platform: windows
port: 
date_added: 2002-02-27  
date_updated: 2012-09-12  
verified: 1  
codes: CVE-2002-0338;OSVDB-14398  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 21307.txt  
source: https://www.securityfocus.com/bid/4187/info

The Bat! is an e-mail client for Microsoft Windows operating systems.

A problem occurs with The Bat! when it is configured to save attachments seperately from the body of a message. It is possible to include a MS-DOS device name (such as CON, AUX, PRN, etc.) in the filename of the attachment to cause a denial of service to an e-mail client with this configuration.

This appears to be an issue with The Bat! version 1.53d. Earlier versions do not appear to be affected.

bash-2.03$ sendmail -U test@test.com
From: test
To: test
Content-Type: apllication/exe; name=lpt1

Test