CREAR AL-Mail32 before 1.13d allows remote attackers to cause a denial of service (application crash) via a (1) CON, (2) AUX, or (3) NUL device name in the filename of an attachment.Referenceshttp://jvn.jp/en/jp/JVN55365709/index.htmlhttp://www.almail.com/vulnerability.htmlhttp://jvndb.jvn.jp/jvndb/JVNDB-2015-000021