CVE-2005-1105: Medium severity Sun Javamail vulnerability
Published Apr 13, 2005
·Updated
Directory traversal vulnerability in the MimeBodyPart.getFileName method in JavaMail 1.3.2 allows remote attackers to write arbitrary files via a .. (dot dot) in the filename in the Content-Disposition header.
Affected Software
1 affected component
Sun Javamail=1.3.2
Event History
Apr 13, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1105?
CVE-2005-1105 is classified as a medium-severity vulnerability due to its potential for arbitrary file writing.
2
How do I fix CVE-2005-1105?
To fix CVE-2005-1105, upgrade to a later version of JavaMail that has patched this vulnerability.
3
What software versions are affected by CVE-2005-1105?
CVE-2005-1105 affects JavaMail version 1.3.2.
4
What type of vulnerability is CVE-2005-1105?
CVE-2005-1105 is a directory traversal vulnerability.
5
Can CVE-2005-1105 be exploited remotely?
Yes, CVE-2005-1105 can be exploited remotely by attackers using specially crafted requests.