First published: Wed Dec 01 2004(Updated: )
MIMEDefang in MIME-tools 5.414 allows remote attackers to bypass virus scanning capabilities via an e-mail attachment with a virus that contains an empty boundary string in the Content-Type header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Roaring Penguin MIMEDefang | =2.42 | |
Roaring Penguin MIMEDefang | =2.4 | |
Roaring Penguin MIMEDefang | =2.14 | |
Roaring Penguin MIMEDefang | =4.47 | |
Roaring Penguin MIMEDefang | =2.43 | |
Roaring Penguin MIMEDefang | =2.38 | |
Roaring Penguin MIMEDefang | =2.39 | |
Roaring Penguin MIMEDefang | =4.46 | |
Roaring Penguin MIMEDefang | =2.21 | |
Roaring Penguin MIMEDefang | =2.45 | |
Roaring Penguin MIMEDefang | =2.20 | |
Roaring Penguin MIMEDefang | =2.41 | |
Roaring Penguin MIMEDefang | =2.44 | |
Mandriva Linux Corporate Server | =2.1 | |
SUSE Linux | =9.2 | |
SUSE Linux | =9.0 | |
SUSE Linux | =8.2 | |
Mandrake Linux | =9.2 | |
SUSE Linux | =9.0 | |
Mandrake Linux | =10.1 | |
SUSE Linux | =8.0 | |
Mandrake Linux | =9.2 | |
SUSE Linux | =9.1 | |
Mandrake Linux | =10.0 | |
SUSE Linux | =8.1 | |
Mandriva Linux Corporate Server | =2.1 | |
Mandrake Linux | =10.0 | |
Mandrake Linux | =10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1098 has been classified as a high severity vulnerability due to its ability to bypass virus scanning mechanisms.
To fix CVE-2004-1098, you should upgrade to a patched version of MIMEDefang that addresses this vulnerability.
CVE-2004-1098 affects MIMEDefang versions 2.14, 2.20, 2.21, 2.38, 2.39, 2.41, 2.42, 2.43, 2.44, 2.45, 4.46, and 4.47.
Yes, CVE-2004-1098 can be exploited remotely via specially crafted email attachments.
CVE-2004-1098 undermines email security by allowing viruses to bypass virus scanning checks in MIMEDefang.