Clearswift MIMEsweeper For Web Executable File Bypass Vulnerability
BID:15982
CVE-2005-4526 |Info
Clearswift MIMEsweeper For Web Executable File Bypass Vulnerability
| Bugtraq ID: | 15982 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 20 2005 12:00AM |
| Updated: | Dec 15 2006 08:53PM |
| Credit: | Discovered by Oliver Muenchow. |
| Vulnerable: |
Clearswift MIMEsweeper For Web 5.1 Clearswift MIMEsweeper For Web 5.0.5 Clearswift MIMEsweeper For Web 5.0.4 Clearswift MIMEsweeper For Web 5.0.3 Clearswift MIMEsweeper For Web 5.0.2 Clearswift MIMEsweeper For Web 5.0.1 Clearswift MIMEsweeper For Web 4.0 |
| Not Vulnerable: | |
Discussion
Clearswift MIMEsweeper For Web Executable File Bypass Vulnerability
Clearswift MIMEsweeper For Web is prone to a file-bypass vulnerability.
An attacker may bypass filters and supply malicious files to computers protected by MIMEsweeper For Web. This may lead to various attacks, including potential arbitrary code execution. Due to the nature of the application, this issue can create a false sense of security for users protected by the application.
All versions of Clearswift MIMEsweeper For Web are considered vulnerable at the moment.
NOTE: The vendor refutes this issue, stating that the vulnerability is unsubstantiated.
Clearswift MIMEsweeper For Web is prone to a file-bypass vulnerability.
An attacker may bypass filters and supply malicious files to computers protected by MIMEsweeper For Web. This may lead to various attacks, including potential arbitrary code execution. Due to the nature of the application, this issue can create a false sense of security for users protected by the application.
All versions of Clearswift MIMEsweeper For Web are considered vulnerable at the moment.
NOTE: The vendor refutes this issue, stating that the vulnerability is unsubstantiated.
Exploit / POC
Clearswift MIMEsweeper For Web Executable File Bypass Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Clearswift MIMEsweeper For Web Executable File Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Clearswift MIMEsweeper For Web Executable File Bypass Vulnerability
References:
References: