CVE-2003-0928: High severity Clearswift MAILsweeper vulnerability
Published Aug 18, 2004
·Updated
Clearswift MAILsweeper before 4.3.15 does not properly detect and filter RAR 3.20 encoded files, which allows remote attackers to bypass intended policy.
Affected Software
1 affected component
Clearswift MAILsweeper<=4.3.15
Event History
Aug 18, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-0928?
CVE-2003-0928 is considered a medium severity vulnerability due to its potential to allow policy bypass in mail filtering.
2
How do I fix CVE-2003-0928?
To fix CVE-2003-0928, upgrade your Clearswift MAILsweeper software to version 4.3.15 or later.
3
What does CVE-2003-0928 allow attackers to do?
CVE-2003-0928 allows remote attackers to bypass intended email filtering policies by exploiting improper detection of RAR 3.20 encoded files.
4
Which versions of Clearswift MAILsweeper are affected by CVE-2003-0928?
Clearswift MAILsweeper versions prior to 4.3.15 are affected by CVE-2003-0928.
5
Is there a workaround for CVE-2003-0928?
There are no specific workarounds for CVE-2003-0928; the recommended approach is to update the software to the latest version.