ZoneLabs ZoneAlarm MailSafe Extension Dot Filtering Bypass Vulnerability
BID:4407
Info
ZoneLabs ZoneAlarm MailSafe Extension Dot Filtering Bypass Vulnerability
| Bugtraq ID: | 4407 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 02 2002 12:00AM |
| Updated: | Apr 02 2002 12:00AM |
| Credit: | Discovered by Edvice Security Services <[email protected]>. |
| Vulnerable: |
Zone Labs ZoneAlarm 3.0 |
| Not Vulnerable: | |
Discussion
ZoneLabs ZoneAlarm MailSafe Extension Dot Filtering Bypass Vulnerability
ZoneLabs ZoneAlarm is a firewall for Microsoft Windows based PCs. It supports a wide range of functions, including a MailSafe feature designed to block email containing malicious content or attachments.
A vulnerability has been reported in some versions of ZoneAlarm. MailSafe may be configured to block file attachments with a certain extension, for example all .exe files. If the same file is sent with an additional '.' appended to the filename, it will not be blocked.
ZoneLabs ZoneAlarm is a firewall for Microsoft Windows based PCs. It supports a wide range of functions, including a MailSafe feature designed to block email containing malicious content or attachments.
A vulnerability has been reported in some versions of ZoneAlarm. MailSafe may be configured to block file attachments with a certain extension, for example all .exe files. If the same file is sent with an additional '.' appended to the filename, it will not be blocked.
Exploit / POC
ZoneLabs ZoneAlarm MailSafe Extension Dot Filtering Bypass Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
ZoneLabs ZoneAlarm MailSafe Extension Dot Filtering Bypass Vulnerability
Solution:
Reportedly, ZoneLabs has resolved this issue. Customers are advised to use the product's Check for Update feature.
Solution:
Reportedly, ZoneLabs has resolved this issue. Customers are advised to use the product's Check for Update feature.
References
ZoneLabs ZoneAlarm MailSafe Extension Dot Filtering Bypass Vulnerability
References:
References:
- Zone Labs Homepage (Zone Labs)