Aladdin Knowledge Systems eSafe OPSEC CVP Virus Scanning Bypass Vulnerability
BID:6787
Info
Aladdin Knowledge Systems eSafe OPSEC CVP Virus Scanning Bypass Vulnerability
| Bugtraq ID: | 6787 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 06 2003 12:00AM |
| Updated: | Feb 06 2003 12:00AM |
| Credit: | Discovery credited to "Igor U.Miturin" <[email protected]>. |
| Vulnerable: |
Aladdin Knowledge Systems eSafe Gateway 3.5 Aladdin Knowledge Systems eSafe Gateway 3.0 |
| Not Vulnerable: | |
Discussion
Aladdin Knowledge Systems eSafe OPSEC CVP Virus Scanning Bypass Vulnerability
It has been reported that under some circumstances, eSafe Gateway does not properly scan messages in transit. This problem occurs when data is passed to eSafe via a Check Point OPSEC CVP compliant firewall. Because of this, malicious code may be able to circumvent the filters imposed by the software and enter, or exit the network. This could lead to further compromise of network resources.
It has been reported that under some circumstances, eSafe Gateway does not properly scan messages in transit. This problem occurs when data is passed to eSafe via a Check Point OPSEC CVP compliant firewall. Because of this, malicious code may be able to circumvent the filters imposed by the software and enter, or exit the network. This could lead to further compromise of network resources.
Exploit / POC
Aladdin Knowledge Systems eSafe OPSEC CVP Virus Scanning Bypass Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Aladdin Knowledge Systems eSafe OPSEC CVP Virus Scanning Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Aladdin Knowledge Systems eSafe OPSEC CVP Virus Scanning Bypass Vulnerability
References:
References:
- eSafe product Homepage (Aladdin Knowledge Systems)
- FW-1 NG FP3 Bug - Data flow problem when transferring large files ("Igor U.Miturin"
)