CVE-2002-0637: High severity Trend Micro InterScan VirusWall vulnerability
InterScan VirusWall 3.52 build 1462 allows remote attackers to bypass virus protection via e-mail messages with headers that violate RFC specifications by having (or missing) space characters in unexpected places (aka "space gap"), such as (1) Content-Type :", (2) "Content-Transfer-Encoding :", (3) no space before a boundary declaration, or (4) "boundary= ", which is processed by Outlook Express.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0637?
CVE-2002-0637 is classified as a medium severity vulnerability, allowing remote attackers to bypass virus protection.
How do I fix CVE-2002-0637?
To fix CVE-2002-0637, upgrade to a newer version of Trend Micro InterScan VirusWall that addresses this vulnerability.
What specific email headers are affected by CVE-2002-0637?
CVE-2002-0637 affects email headers including Content-Type and Content-Transfer-Encoding, where space characters can be improperly placed.
Can CVE-2002-0637 be exploited remotely?
Yes, CVE-2002-0637 can be exploited remotely, allowing attackers to send malicious emails that bypass virus scanning.
Which version of InterScan VirusWall is impacted by CVE-2002-0637?
CVE-2002-0637 specifically impacts InterScan VirusWall version 3.52.