PDA

View Full Version : The Bat! PGP Message Recursion Flaw May Permit Remote Code Execution


bigc73542
January 18th, 2004, 07:18 PM
Link to story: http://www.securitytracker.com/alerts/2004/Jan/1008740.html
- URL tags added to the link - everyone, please do this yourself! - paul

-{ Quote: "The Bat! PGP Message Recursion Flaw May Permit Remote Code Execution

SecurityTracker Alert ID: 1008740
CVE Reference: GENERIC-MAP-NOMATCH
Date: Jan 16 2004
Impact: Execution of arbitrary code via network, User access via network
Version(s): 2.01
Description: A vulnerability was reported in The Bat! in the processing of PGP-signed messages. A remote user may be able to execute arbitrary code.

It is reported that a remote user can send a specially crafted PGP-signed e-mail message with multiple recursively included MIME parts to trigger the flaw and cause a handled exception on the target system...

.
.
." }-