CVE-2004-1517: High severity Zonelabs Imsecure vulnerability
Published Dec 31, 2004
·Updated
Zone Labs IMsecure and IMsecure Pro before 1.5 allow remote attackers to bypass Active Link Filtering via an instant message containing a URL with hex encoded file extensions.
Affected Software
3 affected components
Zonelabs Imsecure=1.0.2.0
Zonelabs Imsecure=1.0.1.0
Zonelabs Imsecure=1.0.0.0
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Feb 19, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1517?
CVE-2004-1517 is considered to be of medium severity since it allows attackers to bypass security filters.
2
How do I fix CVE-2004-1517?
To fix CVE-2004-1517, upgrade to Zone Labs IMsecure version 1.5 or later.
3
What applications are affected by CVE-2004-1517?
CVE-2004-1517 affects Zone Labs IMsecure versions 1.0.0.0 through 1.0.2.0.
4
Can CVE-2004-1517 lead to remote code execution?
No, CVE-2004-1517 does not lead to remote code execution but allows bypassing of content filtering.
5
What is the nature of the vulnerability in CVE-2004-1517?
CVE-2004-1517 allows remote attackers to bypass Active Link Filtering through specially crafted instant messages.