PT-2002-2123 · Roaring Penguin+2 · Mimedefang+2

Publicado

2002-09-14

·

Atualizado

2016-10-18

·

CVE-2002-1121

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: GFI MailSecurity for Exchange/SMTP versions prior to 7.2 InterScan VirusWall versions prior to 3.52 build 1494 MIMEDefang versions prior to 2.21
Description: The issue concerns SMTP content filter engines that do not detect fragmented emails as defined in RFC2046, allowing remote attackers to bypass content filtering, including virus checking, via fragmented emails of the message/partial content type. This could potentially affect a significant number of devices worldwide, although the exact number is not specified.
Recommendations: For GFI MailSecurity for Exchange/SMTP versions prior to 7.2, update to version 7.2 or later to resolve the issue. For InterScan VirusWall versions prior to 3.52 build 1494, update to version 3.52 build 1494 or later to resolve the issue. For MIMEDefang versions prior to 2.21, update to version 2.21 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1121

Produtos afetados

Gfi Mailsecurity For Exchange
Interscan Viruswall
Mimedefang