CVE-2008-5540: Input Validation
Secure Computing Secure Web Gateway (aka Webwasher), when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5540?
The severity of CVE-2008-5540 is rated as critical with a score of 9.3.
How do I fix CVE-2008-5540?
To fix CVE-2008-5540, ensure that you are using an updated version of Secure Computing Secure Web Gateway or Secure Computing Webwasher that addresses this vulnerability.
What systems are affected by CVE-2008-5540?
CVE-2008-5540 affects Secure Computing Secure Web Gateway and Secure Computing Webwasher when used with Internet Explorer 6 or 7.
What type of attacks can be performed with CVE-2008-5540?
CVE-2008-5540 allows remote attackers to bypass malware detection in HTML documents, leading to potential malware execution.
When was CVE-2008-5540 published?
CVE-2008-5540 was published on December 12, 2008.