CVE-2006-0630

UnknownEPSS 1.60%

Last modified

CVE-2006-0630 is a vulnerability of currently unknown severity. RITLabs The Bat! before 3.0.0.15 displays certain important headers from encapsulated data in message/partial MIME messages, instead of the real headers, which is in violation of RFC2046 header merging rules and allows remote attackers to spoof the origin of e-mail by sending a fragmented message, as demonstrated using spoofed Received: and Message-ID: headers.. EPSS estimates a 1.60% chance of exploitation in the next 30 days.

Description

RITLabs The Bat! before 3.0.0.15 displays certain important headers from encapsulated data in message/partial MIME messages, instead of the real headers, which is in violation of RFC2046 header merging rules and allows remote attackers to spoof the origin of e-mail by sending a fragmented message, as demonstrated using spoofed Received: and Message-ID: headers.

Metrics

EPSS Probability
1.60%

72.7th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
RitlabsThe Bat3.0
RitlabsThe Bat3.0.0.7
RitlabsThe Bat3.0.0.8
RitlabsThe Bat3.0.0.9
RitlabsThe Bat3.0.0.10
RitlabsThe Bat3.0.0.11
RitlabsThe Bat3.0.0.12
RitlabsThe Bat3.0.0.14

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2006-0630?
RITLabs The Bat! before 3.0.0.15 displays certain important headers from encapsulated data in message/partial MIME messages, instead of the real headers, which is in violation of RFC2046 header merging rules and allows remote attackers to spoof the origin of e-mail by sending a fragmented message, as demonstrated using spoofed Received: and Message-ID: headers.
How severe is CVE-2006-0630?
Severity scoring for CVE-2006-0630 is pending analysis. The EPSS model estimates a 1.60% probability of exploitation in the next 30 days.
How do I fix CVE-2006-0630?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2006-0630?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST