POP3: .GRP
This signature detects GRP files sent over POP3. GRP files can contain Windows Program Group information and can be exploited by malcious users to deposit instructions or arbritrary code on a target's system. User involvement is required to activate GRP files; typically they are attached to a harmless-appearing e-mail message.
Extended Description
Microsoft Windows operating systems have been reported to be prone to a remotely exploitable buffer overrun condition. This issue is exposed when a client attempts to connect to an SMB share with an overly long name. This may cause explorer.exe or Internet Explorer to crash but could also potentially be leveraged to execute arbitrary code as the client user.
Affected Products
Avaya s8100_media_servers,Microsoft windows_98
References
BugTraq: 10213
CVE: CVE-2004-0214
URL: http://www.internetfixes.com/file_ext.htm http://www.microsoft.com/technet/security/bulletin/MS04-037.mspx
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Microsoft
Avaya
10.0