漏洞信息详情
SMTP加密电子邮件扫描 Clearswift MIMEsweeper绕过漏洞
漏洞简介
用于SMTP 4.3版本或MAILsweeper Business Suite I或II的Clearswift从MAILsweeper升级到Clearswift MIMEsweeper 5.0.5版本时存在漏洞。远程攻击者可以通过在邮件信息中包含加密信息绕过扫描,该漏洞导致信息被标志为\"Clean\"而不是\"Encrypted\"。
漏洞公告
Clearswift have released version 5.0.5 to address this issue. Those affected by this vulnerability should contact the vendor to obtain updates.
参考网址
来源: XF 名称: mimesweeper-smtp-scan-bypass(18035) 链接:http://xforce.iss.net/xforce/xfdb/18035 来源: BID 名称: 11669 链接:http://www.securityfocus.com/bid/11669 来源: OSVDB 名称: 11602 链接:http://www.osvdb.org/11602 来源: SECUNIA 名称: 13160 链接:http://secunia.com/advisories/13160 来源: download.mimesweeper.com 链接:http://download.mimesweeper.com/www/TechnicalDocumentation/MSWSMTP505UpdateReadMe.htm
受影响实体
- Clearswift Mailsweeper_for_smtp:4.3<!--2000-1-1-->
- Clearswift Mimesweeper_for_web:5.0.5<!--2000-1-1-->
- Clearswift Mailsweeper_business_suite_i<!--2000-1-1-->
- Clearswift Mailsweeper_business_suite_ii<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...