Clearswift MAILsweeper for SMTP Archive File Filtering Bypass Vulnerability
BID:10940
Info
Clearswift MAILsweeper for SMTP Archive File Filtering Bypass Vulnerability
| Bugtraq ID: | 10940 |
| Class: | Design Error |
| CVE: |
CVE-2003-0928 CVE-2003-0929 CVE-2003-0930 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 13 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | Discovery is credited to Corsaire. |
| Vulnerable: |
Clearswift MailSweeper 4.3.14 Clearswift MailSweeper 4.3.13 Clearswift MailSweeper 4.3.11 Clearswift MailSweeper 4.3.10 Clearswift MailSweeper 4.3.8 Clearswift MailSweeper 4.3.7 Clearswift MailSweeper 4.3.6 SP1 Clearswift MailSweeper 4.3.6 Clearswift MailSweeper 4.3.5 Clearswift MailSweeper 4.3.4 Clearswift MailSweeper 4.3.3 Clearswift MailSweeper 4.3 Clearswift MailSweeper 4.2 Clearswift MailSweeper 4.1 Clearswift MailSweeper 4.0 |
| Not Vulnerable: |
Clearswift MailSweeper 4.3.15 |
Discussion
Clearswift MAILsweeper for SMTP Archive File Filtering Bypass Vulnerability
It is reported that MAILsweeper for SMTP does not filter malicious archives of various formats. The application does not detect malicious content or file names of archives contained in email. Some of the formats not detected by the application include 7ZIP, ACE, ARC, BH, BZIP2, HAP, HPK, IMG, PAK, RAR, and ZOO.
Successful exploitation may allow malicious code to be executed on client systems. Exploitation can only occur if a user executes a malicious attachment and malicious files must also bypass any local anti virus software.
MAILsweeper for SMTP versions prior to 4.3.15 are reported affected by this issue. This issue may be related to BID 8982 (Clearswift MAILsweeper for SMTP Zip Archive Filtering Bypass Vulnerability).
It is reported that MAILsweeper for SMTP does not filter malicious archives of various formats. The application does not detect malicious content or file names of archives contained in email. Some of the formats not detected by the application include 7ZIP, ACE, ARC, BH, BZIP2, HAP, HPK, IMG, PAK, RAR, and ZOO.
Successful exploitation may allow malicious code to be executed on client systems. Exploitation can only occur if a user executes a malicious attachment and malicious files must also bypass any local anti virus software.
MAILsweeper for SMTP versions prior to 4.3.15 are reported affected by this issue. This issue may be related to BID 8982 (Clearswift MAILsweeper for SMTP Zip Archive Filtering Bypass Vulnerability).
Exploit / POC
Clearswift MAILsweeper for SMTP Archive File Filtering Bypass Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Clearswift MAILsweeper for SMTP Archive File Filtering Bypass Vulnerability
Solution:
MAILsweeper for SMTP 4.3.15 is available to address this issue. Please contact the vendor to obtain the fixed version. This information has not been confirmed by Symantec.
Solution:
MAILsweeper for SMTP 4.3.15 is available to address this issue. Please contact the vendor to obtain the fixed version. This information has not been confirmed by Symantec.
References
Clearswift MAILsweeper for SMTP Archive File Filtering Bypass Vulnerability
References:
References:
- Home Page (Clearswift)
- ReadMe for MAILsweeper for SMTP 4.3.15 (Clearswift)
- Clearswift MAILsweeper multiple encoding/compression issues ("advisories"
)