PT-2005-4349 · Zonealarm · Zonealarm Pro+4
Debasis Mohanty
+1
·
Publicado
2005-11-16
·
Atualizado
2017-07-11
·
CVE-2005-3560
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ZoneAlarm Pro version 6.0
ZoneAlarm Internet Security Suite version 6.0
ZoneAlarm Anti-Virus version 6.0
ZoneAlarm Anti-Spyware versions 6.0 through 6.1
ZoneAlarm version 6.0
Description
The issue allows remote attackers to bypass the Advanced Program Control and OS Firewall filters setting. This can be achieved via URLs in HTML Modal Dialogs, specifically through the
window.location.href property contained within JavaScript tags.Recommendations
For ZoneAlarm Pro version 6.0, update to a version that addresses this issue.
For ZoneAlarm Internet Security Suite version 6.0, update to a version that addresses this issue.
For ZoneAlarm Anti-Virus version 6.0, update to a version that addresses this issue.
For ZoneAlarm Anti-Spyware versions 6.0 through 6.1, update to a version that addresses this issue.
For ZoneAlarm version 6.0, update to a version that addresses this issue.
As a temporary workaround, consider restricting the use of JavaScript tags until a patch is available.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Zonealarm
Zonealarm Anti-Spyware
Zonealarm Antivirus
Zonealarm Internet Security Suite
Zonealarm Pro