Network Associates WebShield SMTP Malformed Mime Header Vulnerability
BID:3601
Info
Network Associates WebShield SMTP Malformed Mime Header Vulnerability
| Bugtraq ID: | 3601 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 29 2001 12:00AM |
| Updated: | Nov 29 2001 12:00AM |
| Credit: | Discovered by Jari Helenius <[email protected]> and posted to the BugTraq mailing list on November 29, 2001. |
| Vulnerable: |
Network Associates VirusScan for Windows NT 4.5 |
| Not Vulnerable: | |
Discussion
Network Associates WebShield SMTP Malformed Mime Header Vulnerability
WebShield SMTP is a gateway product designed to parse and scan incoming email for malicious content, including virus and worm attachments. MIME is a standard encoding scheme used for multi-part messages, including file attachments in email.
The MIME encoded file attachments that do not follow the MIME specification may not be recognized as attachments by WebShield. Some email clients, however, will recognize these malformed MIME encodings as valid, treating this content as a valid file attachment.
As WebShield does not recognize the content as an attachment, it is not subject to file based content filtering rules. Additionally, it will not be passed to the virus scanner.
Older versions of WebShield may also be vulnerable.
WebShield SMTP is a gateway product designed to parse and scan incoming email for malicious content, including virus and worm attachments. MIME is a standard encoding scheme used for multi-part messages, including file attachments in email.
The MIME encoded file attachments that do not follow the MIME specification may not be recognized as attachments by WebShield. Some email clients, however, will recognize these malformed MIME encodings as valid, treating this content as a valid file attachment.
As WebShield does not recognize the content as an attachment, it is not subject to file based content filtering rules. Additionally, it will not be passed to the virus scanner.
Older versions of WebShield may also be vulnerable.
References
Network Associates WebShield SMTP Malformed Mime Header Vulnerability
References:
References:
- WebShield SMTP Product Home Page (Network Associates Inc.)