First published: Wed Aug 18 2004(Updated: )
Clearswift MAILsweeper before 4.3.15 does not properly detect and filter RAR 3.20 encoded files, which allows remote attackers to bypass intended policy.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Clearswift MAILsweeper | <=4.3.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0928 is considered a medium severity vulnerability due to its potential to allow policy bypass in mail filtering.
To fix CVE-2003-0928, upgrade your Clearswift MAILsweeper software to version 4.3.15 or later.
CVE-2003-0928 allows remote attackers to bypass intended email filtering policies by exploiting improper detection of RAR 3.20 encoded files.
Clearswift MAILsweeper versions prior to 4.3.15 are affected by CVE-2003-0928.
There are no specific workarounds for CVE-2003-0928; the recommended approach is to update the software to the latest version.