CVE-2003-1154: High severity Clearswift MAILsweeper vulnerability
Published Dec 31, 2003
·Updated
MAILsweeper for SMTP 4.3 allows remote attackers to bypass virus protection via a mail message with a malformed zip attachment, as exploited by certain MIMAIL virus variants.
Affected Software
12 affected components
Clearswift MAILsweeper=4.3
Clearswift MAILsweeper=4.3.6
Clearswift MAILsweeper=4.0
Clearswift MAILsweeper=4.3.4
Clearswift MAILsweeper=4.2
Clearswift MAILsweeper=4.3.7
Clearswift MAILsweeper=4.3.3
Clearswift MAILsweeper=4.3.5
Clearswift MAILsweeper=4.1
Clearswift MAILsweeper=4.3.10
Clearswift MAILsweeper=4.3.8
Clearswift MAILsweeper=4.3.6_sp1
Remediation
Patch Available
Event History
Dec 31, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
May 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1154?
CVE-2003-1154 is considered to be of medium severity due to its potential for virus bypassing security measures.
2
How do I fix CVE-2003-1154?
To fix CVE-2003-1154, it's recommended to upgrade to the latest version of MAILsweeper that addresses this vulnerability.
3
Which versions of MAILsweeper are affected by CVE-2003-1154?
CVE-2003-1154 affects multiple versions of MAILsweeper including 4.0, 4.1, 4.2, 4.3.3 through 4.3.10.
4
What can attackers do by exploiting CVE-2003-1154?
By exploiting CVE-2003-1154, attackers can bypass virus protection mechanisms when using malformed zip attachments.
5
Is there a patch available for CVE-2003-1154?
Yes, a patch or updated version is available from Clearswift to mitigate the risks associated with CVE-2003-1154.