PT-2005-4349 · Zonealarm · Zonealarm Pro+4

Debasis Mohanty

+1

·

Publicado

2005-11-16

·

Atualizado

2017-07-11

·

CVE-2005-3560

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ZoneAlarm Pro version 6.0 ZoneAlarm Internet Security Suite version 6.0 ZoneAlarm Anti-Virus version 6.0 ZoneAlarm Anti-Spyware versions 6.0 through 6.1 ZoneAlarm version 6.0
Description The issue allows remote attackers to bypass the Advanced Program Control and OS Firewall filters setting. This can be achieved via URLs in HTML Modal Dialogs, specifically through the window.location.href property contained within JavaScript tags.
Recommendations For ZoneAlarm Pro version 6.0, update to a version that addresses this issue. For ZoneAlarm Internet Security Suite version 6.0, update to a version that addresses this issue. For ZoneAlarm Anti-Virus version 6.0, update to a version that addresses this issue. For ZoneAlarm Anti-Spyware versions 6.0 through 6.1, update to a version that addresses this issue. For ZoneAlarm version 6.0, update to a version that addresses this issue. As a temporary workaround, consider restricting the use of JavaScript tags until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-3560

Produtos afetados

Zonealarm
Zonealarm Anti-Spyware
Zonealarm Antivirus
Zonealarm Internet Security Suite
Zonealarm Pro