PT-2005-4349 · Zonealarm · Zonealarm Pro+4
Debasis Mohanty
+1
·
Published
2005-11-16
·
Updated
2017-07-11
·
CVE-2005-3560
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ZoneAlarm Pro version 6.0
ZoneAlarm Internet Security Suite version 6.0
ZoneAlarm Anti-Virus version 6.0
ZoneAlarm Anti-Spyware versions 6.0 through 6.1
ZoneAlarm version 6.0
Description
The issue allows remote attackers to bypass the Advanced Program Control and OS Firewall filters setting. This can be achieved via URLs in HTML Modal Dialogs, specifically through the
window.location.href property contained within JavaScript tags.Recommendations
For ZoneAlarm Pro version 6.0, update to a version that addresses this issue.
For ZoneAlarm Internet Security Suite version 6.0, update to a version that addresses this issue.
For ZoneAlarm Anti-Virus version 6.0, update to a version that addresses this issue.
For ZoneAlarm Anti-Spyware versions 6.0 through 6.1, update to a version that addresses this issue.
For ZoneAlarm version 6.0, update to a version that addresses this issue.
As a temporary workaround, consider restricting the use of JavaScript tags until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zonealarm
Zonealarm Anti-Spyware
Zonealarm Antivirus
Zonealarm Internet Security Suite
Zonealarm Pro