First published: Fri Dec 31 2004(Updated: )
Clearswift MIMEsweeper 5.0.5, when it has been upgraded from MAILsweeper for SMTP version 4.3 or MAILsweeper Business Suite I or II, allows remote attackers to bypass scanning by including encrypted data in a mail message, which causes the message to be marked as "Clean" instead of "Encrypted".
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Clearswift MAILsweeper Business Suite | ||
Clearswift MAILsweeper | ||
Clearswift MAILsweeper | =4.3 | |
Clearswift MIMEsweeper for Web | =5.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2703 is classified as a medium severity vulnerability due to its potential to bypass scanning for encrypted data.
To mitigate CVE-2004-2703, it is recommended to update or patch the affected Clearswift MIMEsweeper software to the latest version.
CVE-2004-2703 affects Clearswift MIMEsweeper 5.0.5 and previous versions of MAILsweeper for SMTP 4.3 and the Business Suite I or II.
Attackers can bypass email scanning by sending encrypted emails that are incorrectly marked as clean, potentially leading to undiscovered threats.
A temporary workaround for CVE-2004-2703 involves configuring mail servers to handle encrypted data differently, although updating the software is the preferred solution.