Short Name |
SMTP:EXT:DOT-ANI |
---|---|
Severity |
Medium |
Recommended |
No |
Category |
SMTP |
Keywords |
.ANI |
Release Date |
2005/01/13 |
Update Number |
1213 |
Supported Platforms |
di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects e-mail attachments that have the extension .ANI (animated cursors) and were sent through SMTP. A vulnerability exists in the way Windows parses ANI and cursor file headers. Attackers can create malicious icon files, tricking users into opening or viewing the file and infecting the system.
Microsoft Windows is prone to a denial of service when processing specially formed ANI files. The Windows kernel fails to perform proper sanitization on the frame or rate number set in the ANI file header, which may result in a system crash.