J-Security Center

Title: Rit Research Labs "The Bat!" X-BAT-FILES Vulnerabilities

Severity: MODERATE

Description:

"The Bat!" is an MUA for Windows by Rit Research Labs. When an attachment is sent to a "The Bat!" user, the software saves the attachment in a specific folder on the system. The path to that folder is then added to the incoming message in the form of a pseudo-header called X-BAT-FILES.

If the message is then forwarded to another recipient, "The Bat!" will leave the pseudo-header line intact, allowing the recipient to see the default location of all saved email attachments for that user.

Also, it is possible to spoof this header, so that if an email is sent to a "The Bat!" user with an X-BAT-FILES line already in the headers, the software will then attach the specified file if that email is forwarded on. For example, if an email is sent from A to B with
X-BAT-FILES: C:\autoexec.bat
and then the message is forwarded to C, C will receive the message along with a copy of B's autoxec.bat

Affected Products:

  • Rit Research Labs The Bat! 1.39.0

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.