Clearswift MIMEsweeper For SMTP Encrypted Email Scanner Bypass Vulnerability
BID:11669
Info
Clearswift MIMEsweeper For SMTP Encrypted Email Scanner Bypass Vulnerability
| Bugtraq ID: | 11669 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 11 2004 12:00AM |
| Updated: | Nov 11 2004 12:00AM |
| Credit: | This issue was announced by the vendor. |
| Vulnerable: |
Clearswift MIMEsweeper for SMTP 5.0 |
| Not Vulnerable: |
Clearswift MIMEsweeper for SMTP 5.0.5 |
Discussion
Clearswift MIMEsweeper For SMTP Encrypted Email Scanner Bypass Vulnerability
A vulnerability has been reported in Clearswift MIMEsweeper that may result in malicious emails bypassing the scanner. This is due to an issue in classifying encrypted emails, causing them to be marked as "clean" instead of being properly flagged as "encrypted".
This issue affects users who have upgraded to MIMEsweeper for SMTP 5.0 from MAILsweeper Business Suite I, MAILsweeper Business Suite II, or MAILsweeper for SMTP version 4.3. Fresh installs of MIMEsweeper for SMTP 5.0 are not affected.
A vulnerability has been reported in Clearswift MIMEsweeper that may result in malicious emails bypassing the scanner. This is due to an issue in classifying encrypted emails, causing them to be marked as "clean" instead of being properly flagged as "encrypted".
This issue affects users who have upgraded to MIMEsweeper for SMTP 5.0 from MAILsweeper Business Suite I, MAILsweeper Business Suite II, or MAILsweeper for SMTP version 4.3. Fresh installs of MIMEsweeper for SMTP 5.0 are not affected.
Exploit / POC
Clearswift MIMEsweeper For SMTP Encrypted Email Scanner Bypass Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Clearswift MIMEsweeper For SMTP Encrypted Email Scanner Bypass Vulnerability
Solution:
Clearswift have released version 5.0.5 to address this issue. Those affected by this vulnerability should contact the vendor to obtain updates.
Solution:
Clearswift have released version 5.0.5 to address this issue. Those affected by this vulnerability should contact the vendor to obtain updates.
References
Clearswift MIMEsweeper For SMTP Encrypted Email Scanner Bypass Vulnerability
References:
References:
- Readme for MIMEsweeper for SMTP 5.0.5 (Clearswift)