CVE-2006-0630: Medium severity Ritlabs The Bat vulnerability
RITLabs The Bat! before 3.0.0.15 displays certain important headers from encapsulated data in message/partial MIME messages, instead of the real headers, which is in violation of RFC2046 header merging rules and allows remote attackers to spoof the origin of e-mail by sending a fragmented message, as demonstrated using spoofed Received: and Message-ID: headers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0630?
CVE-2006-0630 has a low to medium severity as it allows spoofing of email origins in specific versions of RITLabs The Bat.
How do I fix CVE-2006-0630?
To fix CVE-2006-0630, upgrade RITLabs The Bat! to version 3.0.0.15 or later.
Who is affected by CVE-2006-0630?
Users of RITLabs The Bat! versions 3.0.0.12, 3.0.0.7, 3.0, 3.0.0.8, 3.0.0.14, 3.0.0.10, 3.0.0.11, and 3.0.0.9 are affected by CVE-2006-0630.
What is the impact of CVE-2006-0630?
The impact of CVE-2006-0630 includes potential email spoofing, which can undermine email trust and security.
Is there a workaround for CVE-2006-0630?
There are no known workarounds for CVE-2006-0630, so updating to a newer version is strongly recommended.