MAILsweeper for SMTP/Exchange character set security bypass
| mailsweeper-charcter-set-security-bypass (27301) |
Description:
MAILsweeper for SMTP/Exchange could allow certain specially-crafted messages to bypass security restrictions. A remote attacker could send a specially-crafted email message that specifies a non-existent character set, which would bypass the text analysis functions, allowing the attacker to bypass email security restrictions.
Consequences:
Bypass Security
Remedy:
Upgrade to the latest version of MAILsweeper for SMTP/Exchange (4.3.20 or later), available from the Clearswift Limited Web site. See References.
References:
- Clearswift Limited Web site: ReadMe for MAILsweeper 4.3_13 (Technology Update Version 1.4_13).
- MIMEsweeper Web site: ReadMe for MAILsweeper for SMTP 4.3.20.
- BID-18584: Clearswift MAILsweeper for SMTP / Exchange Multiple Vulnerabilities
- CVE-2006-3215: Clearswift MAILsweeper for SMTP before 4.3.20 and MAILsweeper for Exchange before 4.3.20 allows remote attackers to bypass the text analysis, possibly bypassing SPAM and other filters, by sending an e-mail specifying a non-existent or unrecognized character set.
- OSVDB ID: 26737: MAILsweeper for SMTP/Exchange Invalid Character Set Scan Bypass
- SA20756: MAILsweeper for SMTP/Exchange Multiple Vulnerabilities
- VUPEN/ADV-2006-2473: Clearswift MAILsweeper Multiple Denial of Service and Security Bypass Vulnerabilities
Platforms Affected:
- Clearswift MAILsweeper for Exchange 4.3.19 and prior
- Clearswift MAILsweeper for SMTP 4.3.19 and prior
Reported:
Jun 21, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
