Finjan SurfinGate Compressed Archive File Filter Circumvention Vulnerability
BID:6706
Info
Finjan SurfinGate Compressed Archive File Filter Circumvention Vulnerability
| Bugtraq ID: | 6706 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 28 2003 12:00AM |
| Updated: | Jan 28 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Compass Security. |
| Vulnerable: |
Finjan Software SurfinGate 7.0 Finjan Software SurfinGate 6.0 5 Finjan Software SurfinGate 6.0 1 Finjan Software SurfinGate 6.0 Finjan Software SurfinGate 5.6 |
| Not Vulnerable: | |
Discussion
Finjan SurfinGate Compressed Archive File Filter Circumvention Vulnerability
A problem with SurfinGate could make it possible for an attacker to circumvent file filters that are set in place.
It has been discovered that SurfinGate does not sufficiently dissect archive files for analysis. This may allow an attacker to circumvent the SurfinGate file filter rules by including a malicious file of a blacklisted type into a file archive (such as '.ZIP' or '.RAR').
SurfinGate versions 6.0 and later may detect that there is possibly a virus in the archive. However, this issue has not been completely addressed as of version 7.0.
A problem with SurfinGate could make it possible for an attacker to circumvent file filters that are set in place.
It has been discovered that SurfinGate does not sufficiently dissect archive files for analysis. This may allow an attacker to circumvent the SurfinGate file filter rules by including a malicious file of a blacklisted type into a file archive (such as '.ZIP' or '.RAR').
SurfinGate versions 6.0 and later may detect that there is possibly a virus in the archive. However, this issue has not been completely addressed as of version 7.0.
Exploit / POC
Finjan SurfinGate Compressed Archive File Filter Circumvention Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Finjan SurfinGate Compressed Archive File Filter Circumvention Vulnerability
Solution:
This issue has not been completely addressed as of version 7.0. The vendor has reported that fixes will be considered in future releases.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
This issue has not been completely addressed as of version 7.0. The vendor has reported that fixes will be considered in future releases.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Finjan SurfinGate Compressed Archive File Filter Circumvention Vulnerability
References:
References:
- SurfinGate Product Page (Finjan Software)
- RE: Tech Article: HTTP Content Filter Analysis - Finjan SurfinGate V5.6 ("Menashe Eliezer"
) - Tech Article: HTTP Content Filter Analysis - Finjan SurfinGate v5.6 ("[email protected]"
)