PT-2002-2718 · Zonealarm · Zonealarm Pro

Published

2002-12-31

·

Updated

2017-07-11

·

CVE-2002-1997

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ZoneAlarm Pro version 3.0
Description The issue allows remote attackers to bypass filtering and possibly execute arbitrary code via email attachments containing a trailing dot after the file extension.
Recommendations For ZoneAlarm Pro version 3.0, consider updating the MailSafe component to prevent attackers from bypassing filtering and executing arbitrary code. As a temporary workaround, restrict the handling of email attachments with trailing dots after the file extension to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1997

Affected Products

Zonealarm Pro