Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments whose Content-Type and Content-Disposition headers are mixed upper and lower case, which is ignored by some mail clients.
The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.
Link | Tags |
---|---|
http://marc.info/?l=vuln-dev&m=101681724810317&w=2 | mailing list |
http://marc.info/?l=bugtraq&m=101684260510079&w=2 | mailing list |