Clearswift MailSweeper PowerPoint File Denial of Service Vulnerability
BID:7562
Info
Clearswift MailSweeper PowerPoint File Denial of Service Vulnerability
| Bugtraq ID: | 7562 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 12 2003 12:00AM |
| Updated: | May 12 2003 12:00AM |
| Credit: | This vulnerability was announced by the vendor. |
| Vulnerable: |
Clearswift MailSweeper 4.3.7 Clearswift MailSweeper 4.3.6 |
| Not Vulnerable: |
Clearswift MailSweeper 4.3.8 |
Discussion
Clearswift MailSweeper PowerPoint File Denial of Service Vulnerability
A vulnerability has been discovered in Clearswift MAILsweeper. The problem occurs when handling PowerPoint files containing malformed attributes. When a malicious file is encountered, MAILsweeper will enter an endless loop. This will effectively cause available system resources to be consumed.
A vulnerability has been discovered in Clearswift MAILsweeper. The problem occurs when handling PowerPoint files containing malformed attributes. When a malicious file is encountered, MAILsweeper will enter an endless loop. This will effectively cause available system resources to be consumed.
Exploit / POC
Clearswift MailSweeper PowerPoint File Denial of Service Vulnerability
No exploit required.
No exploit required.
Solution / Fix
Clearswift MailSweeper PowerPoint File Denial of Service Vulnerability
Solution:
Clearswift has released MAILsweeper 4.3.8 to address this issue. Users are advised to upgrade as soon as possible. Further information can be obtained by contacting the vendor.
Solution:
Clearswift has released MAILsweeper 4.3.8 to address this issue. Users are advised to upgrade as soon as possible. Further information can be obtained by contacting the vendor.
References
Clearswift MailSweeper PowerPoint File Denial of Service Vulnerability
References:
References:
- Home Page (Clearswift)
- ReadMe for MAILsweeper for SMTP Version 4.3.8 (Clearswift)