PT-2002-2718 · Zonealarm · Zonealarm Pro
Published
2002-12-31
·
Updated
2017-07-11
·
CVE-2002-1997
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ZoneAlarm Pro version 3.0
Description
The issue allows remote attackers to bypass filtering and possibly execute arbitrary code via email attachments containing a trailing dot after the file extension.
Recommendations
For ZoneAlarm Pro version 3.0, consider updating the MailSafe component to prevent attackers from bypassing filtering and executing arbitrary code. As a temporary workaround, restrict the handling of email attachments with trailing dots after the file extension to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zonealarm Pro