Clearswift MailSweeper Attachment Classification Failure Weakness
BID:7226
Info
Clearswift MailSweeper Attachment Classification Failure Weakness
| Bugtraq ID: | 7226 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 03 2003 12:00AM |
| Updated: | Feb 03 2003 12:00AM |
| Credit: | This issue was announced by Clearswift. |
| Vulnerable: |
Clearswift MailSweeper 4.3.6 SP1 |
| Not Vulnerable: |
Clearswift MailSweeper 4.3.7 |
Discussion
Clearswift MailSweeper Attachment Classification Failure Weakness
MAILsweeper is prone to a weakness that could allow potentially malicious attachments to bypass the filter. This issue occurs because the software fails to act upon user-defined events when the software is configured to strip certain attachment types but fails to actually strip the attachment.
MAILsweeper is prone to a weakness that could allow potentially malicious attachments to bypass the filter. This issue occurs because the software fails to act upon user-defined events when the software is configured to strip certain attachment types but fails to actually strip the attachment.
Exploit / POC
Clearswift MailSweeper Attachment Classification Failure Weakness
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Clearswift MailSweeper Attachment Classification Failure Weakness
Solution:
This issue has been addressed in MAILsweeper for SMTP Version 4.3.7, which is available to users with a support contract.
Solution:
This issue has been addressed in MAILsweeper for SMTP Version 4.3.7, which is available to users with a support contract.