PT-2005-3863 · Sybari · Sybari Antigen
Alan G. Monaghan
·
Publicado
2005-09-21
·
Atualizado
2017-07-11
·
CVE-2005-3027
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Sybari Antigen version 8.0 SR2
Description
The issue allows remote attackers to bypass custom filter rules and send file attachments of arbitrary file types via a message with a subject of "Antigen forwarded attachment". This occurs because Sybari Antigen 8.0 SR2 does not properly filter SMTP messages.
Recommendations
For Sybari Antigen version 8.0 SR2, consider implementing additional filtering rules to restrict file attachments based on type to mitigate the risk of exploitation. As a temporary workaround, restrict the ability to send messages with subjects that could bypass existing filter rules.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sybari Antigen