CVE-2003-1485: Input Validation
Clearswift MAILsweeper 4.0 through 4.3.7 allows remote attackers to bypass filtering via a file attachment that contains "multiple extensions combined with large blocks of white space."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-1485?
CVE-2003-1485 is considered a medium-risk vulnerability due to its potential to bypass email filtering.
How do I fix CVE-2003-1485?
To fix CVE-2003-1485, it is recommended to upgrade to the latest version of Clearswift MAILsweeper available at the time.
What versions of Clearswift MAILsweeper are affected by CVE-2003-1485?
CVE-2003-1485 affects Clearswift MAILsweeper versions from 4.0 to 4.3.7.
What type of attack does CVE-2003-1485 facilitate?
CVE-2003-1485 allows remote attackers to circumvent file attachment filtering by manipulating file names through whitespace.
Is there a workaround for CVE-2003-1485 if upgrading is not possible?
If upgrading is not feasible, administrators should review email filtering configurations and monitor attachments closely for suspicious filenames.