Clearswift MailSweeper Malformed MIME Attachment Filter Bypass Vulnerability
BID:7044
Info
Clearswift MailSweeper Malformed MIME Attachment Filter Bypass Vulnerability
| Bugtraq ID: | 7044 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2003-0121 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 07 2003 12:00AM |
| Updated: | Jul 11 2009 08:06PM |
| Credit: | Discovery is credited to Martin O'Neal <[email protected]>. |
| Vulnerable: |
Clearswift MailSweeper 4.3.6 SP1 Clearswift MailSweeper 4.3 Clearswift MailSweeper 4.2 Clearswift MailSweeper 4.1 Clearswift MailSweeper 4.0 |
| Not Vulnerable: |
Clearswift MailSweeper 4.3.7 |
Discussion
Clearswift MailSweeper Malformed MIME Attachment Filter Bypass Vulnerability
Clearswift MailSweeper does not properly process certain malformed MIME email message attachments. If the attachment does not contain a MIME-Version field, MailSweeper does not recognize the attachment as being an executable type. MailSweeper allows such attachments through, even if it is set to filter executable type file attachments from incoming email messages.
Clearswift MailSweeper does not properly process certain malformed MIME email message attachments. If the attachment does not contain a MIME-Version field, MailSweeper does not recognize the attachment as being an executable type. MailSweeper allows such attachments through, even if it is set to filter executable type file attachments from incoming email messages.
Exploit / POC
Clearswift MailSweeper Malformed MIME Attachment Filter Bypass Vulnerability
There is no exploit code required. Removing the MIME-Version from an encoded attachment will sufficiently bypass the filter.
The following proof of concept was provided by [email protected] <[email protected]>:
There is no exploit code required. Removing the MIME-Version from an encoded attachment will sufficiently bypass the filter.
The following proof of concept was provided by [email protected] <[email protected]>:
Solution / Fix
Clearswift MailSweeper Malformed MIME Attachment Filter Bypass Vulnerability
Solution:
The vendor has released a fix for this issue, which is available to registered users at the following location:
http://www.clearswift.com/download/SQL/downloadList.asp?productID=301
This issue has been addressed in MAILsweeper for SMTP Version 4.3.7, which is available to users with a support contract.
Solution:
The vendor has released a fix for this issue, which is available to registered users at the following location:
http://www.clearswift.com/download/SQL/downloadList.asp?productID=301
This issue has been addressed in MAILsweeper for SMTP Version 4.3.7, which is available to users with a support contract.
References
Clearswift MailSweeper Malformed MIME Attachment Filter Bypass Vulnerability
References:
References:
- Home Page (Clearswift)
- ReadMe for MAILsweeper for SMTP Version 4.3.7 (Clearswift)
- Script Tool (Universal Simple String Detection) (Clearswift)
- Corsaire Security Advisory - Clearswift MAILsweeper MIME attachment evasion issu (Martin O'Neal
) - RE: Corsaire Security Advisory - Clearswift MAILsweeper MIME attachment evasion (Martin O'Neal
)