CVE-2003-0930: High severity Clearswift MAILsweeper vulnerability
Published Aug 18, 2004
·Updated
Clearswift MAILsweeper before 4.3.15 does not properly detect filenames in BinHex (HQX) encoded files, which allows remote attackers to bypass intended policy.
Affected Software
1 affected component
Clearswift MAILsweeper<=4.3.15
Remediation
Patch Available
Event History
Aug 18, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-0930?
CVE-2003-0930 is classified as a moderate severity vulnerability that allows remote attackers to bypass security policy.
2
How do I fix CVE-2003-0930?
To fix CVE-2003-0930, upgrade to Clearswift MAILsweeper version 4.3.15 or later.
3
What types of attacks are possible due to CVE-2003-0930?
CVE-2003-0930 allows attackers to send encoded files that could bypass intended security controls.
4
Which versions of Clearswift MAILsweeper are affected by CVE-2003-0930?
All versions of Clearswift MAILsweeper prior to 4.3.15 are affected by CVE-2003-0930.
5
Are there any workarounds for CVE-2003-0930?
The recommended mitigation for CVE-2003-0930 is to apply the latest software updates rather than relying on workarounds.