MAILsweeper for SMTP "On strip unsuccessful" filter bypass
| mailsweeper-onstrip-bypass-filter (11745) |
Description:
MAILsweeper for SMTP could allow a remote attacker to bypass mail attachment filtering mechanisms. If an attachment is detected and cannot be removed from a message, MAILsweeper for SMTP fails to properly follow the classification that is configured for the "On strip unsuccessful" scenario. By creating a malformed MIME attachment, a remote attacker could bypass mail attachment filtering mechanisms and deliver a malicious executable file to the affected system.
Platforms Affected:
- Clearswift, MAILsweeper for SMTP 4.3.6 SP1
Remedy:
Upgrade to the latest version of MAILsweeper for SMTP (4.3.7 or later), available from the Clearswift Limited Web site. See References.
Consequences:
Bypass Security
References:
- Clearswift Limited Web site, Website Registration - ReadMe for MAILsweeper for SMTP Version 4.3.7 (Technology Update Version 1.4.6) at http://www.mimesweeper.com/logon/default.aspx?R=%2fsupport%2fmsw%2foldproducts.aspx.
- Clearswift Limited Web site, Current Patches at http://www.clearswift.com/support/msw/patch.aspx.
- BID-7226: Clearswift MailSweeper Attachment Classification Failure Weakness
- CVE-2003-1330: Clearswift MAILsweeper for SMTP 4.3.6 SP1 does not execute custom on strip unsuccessful hooks, which allows remote attackers to bypass e-mail attachment filtering policies via an attachment that MAILsweeper can detect but not remove.
Reported:
Feb 03, 2003
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
