PT-2005-3863 · Sybari · Sybari Antigen
Alan G. Monaghan
·
Published
2005-09-21
·
Updated
2017-07-11
·
CVE-2005-3027
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Sybari Antigen version 8.0 SR2
Description
The issue allows remote attackers to bypass custom filter rules and send file attachments of arbitrary file types via a message with a subject of "Antigen forwarded attachment". This occurs because Sybari Antigen 8.0 SR2 does not properly filter SMTP messages.
Recommendations
For Sybari Antigen version 8.0 SR2, consider implementing additional filtering rules to restrict file attachments based on type to mitigate the risk of exploitation. As a temporary workaround, restrict the ability to send messages with subjects that could bypass existing filter rules.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sybari Antigen