First published: Wed Jul 18 2001(Updated: )
MailSafe in Zone Labs ZoneAlarm 2.6 and earlier and ZoneAlarm Pro 2.6 and 2.4 does not block prohibited file types with long file names, which allows remote attackers to send potentially dangerous attachments.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Alarm | =2.1 | |
Alarm | =2.2 | |
Alarm | =2.3 | |
Alarm | =2.4 | |
Alarm | =2.4 | |
Alarm | =2.5 | |
Alarm | =2.6 | |
Alarm | =2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1373 has been classified with a moderate severity level due to the potential for remote attackers to exploit the vulnerability.
To fix CVE-2001-1373, immediately update ZoneAlarm to the latest version where this vulnerability is addressed.
CVE-2001-1373 affects ZoneAlarm versions 2.1, 2.2, 2.3, 2.4, 2.5, and 2.6, including both standard and Pro editions.
CVE-2001-1373 exploits the failure of MailSafe to block prohibited file types with long file names, allowing unsafe attachments.
There is no official workaround for CVE-2001-1373, and the best protection is to update ZoneAlarm to a safe version.