First published: Sat Sep 14 2002(Updated: )
SMTP content filter engines, including (1) GFI MailSecurity for Exchange/SMTP before 7.2, (2) InterScan VirusWall before 3.52 build 1494, (3) the default configuration of MIMEDefang before 2.21, and possibly other products, do not detect fragmented emails as defined in RFC2046 ("Message Fragmentation and Reassembly") and supported in such products as Outlook Express, which allows remote attackers to bypass content filtering, including virus checking, via fragmented emails of the message/partial content type.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GFI MailSecurity | =7.2 | |
Trend Micro Interscan VirusWall | =3.51 | |
Roaring Penguin MIMEDefang | =2.14 | |
Network Associates Webshield Smtp | =4.0.5 | |
Trend Micro Interscan VirusWall | =3.5 | |
Roaring Penguin Canit | =1.2 | |
Network Associates Webshield Smtp | =4.5.44 | |
Roaring Penguin MIMEDefang | =2.20 | |
Network Associates Webshield Smtp | =4.5.74.0 | |
Trend Micro Interscan VirusWall | =3.52 | |
Network Associates Webshield Smtp | =4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.