PT-2005-4349 · Zonealarm · Zonealarm Pro+4

Debasis Mohanty

+1

·

Published

2005-11-16

·

Updated

2017-07-11

·

CVE-2005-3560

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ZoneAlarm Pro version 6.0 ZoneAlarm Internet Security Suite version 6.0 ZoneAlarm Anti-Virus version 6.0 ZoneAlarm Anti-Spyware versions 6.0 through 6.1 ZoneAlarm version 6.0
Description The issue allows remote attackers to bypass the Advanced Program Control and OS Firewall filters setting. This can be achieved via URLs in HTML Modal Dialogs, specifically through the window.location.href property contained within JavaScript tags.
Recommendations For ZoneAlarm Pro version 6.0, update to a version that addresses this issue. For ZoneAlarm Internet Security Suite version 6.0, update to a version that addresses this issue. For ZoneAlarm Anti-Virus version 6.0, update to a version that addresses this issue. For ZoneAlarm Anti-Spyware versions 6.0 through 6.1, update to a version that addresses this issue. For ZoneAlarm version 6.0, update to a version that addresses this issue. As a temporary workaround, consider restricting the use of JavaScript tags until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3560

Affected Products

Zonealarm
Zonealarm Anti-Spyware
Zonealarm Antivirus
Zonealarm Internet Security Suite
Zonealarm Pro