First published: Wed Apr 14 2004(Updated: )
ZoneAlarm Pro 4.5.538.001 and possibly other versions allows remote attackers to bypass e-mail protection via attachments whose names contain certain non-English characters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zonelabs ZoneAlarm | =4.0 | |
Zonelabs ZoneAlarm | =2.6 | |
Zonelabs ZoneAlarm | =2.4 | |
Zonelabs ZoneAlarm | =4.5.538.001 | |
Zonelabs ZoneAlarm | =4.0 | |
Zonelabs ZoneAlarm | =4.5.538.001 | |
Zonelabs ZoneAlarm | =3.1 | |
Zonelabs ZoneAlarm | =4.5 | |
Zonelabs ZoneAlarm | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1936 has a moderate severity rating due to its potential to allow remote attackers to bypass email protection.
To fix CVE-2004-1936, users should update to the latest version of ZoneAlarm that addresses this vulnerability.
CVE-2004-1936 affects ZoneAlarm Pro versions 2.4, 2.6, 3.1, 4.0, 4.5, and 4.5.538.001.
The impact of CVE-2004-1936 allows remote attackers to potentially deliver malicious email attachments that evade security measures.
While specific exploitations of CVE-2004-1936 may not be well-documented, the vulnerability can theoretically be exploited by attackers using specially crafted emails.