First published: Tue Mar 14 2017(Updated: )
File extension filtering vulnerability in Intel Security McAfee Email Gateway (MEG) before 7.6.404h1128596 allows attackers to fail to identify the file name properly via scanning an email with a forged attached filename that uses a null byte within the filename extension.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Email Gateway | <=7.6.401 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8005 is considered a medium severity vulnerability due to its potential to bypass file extension filtering.
To fix CVE-2016-8005, upgrade Intel Security McAfee Email Gateway to version 7.6.404 or later.
CVE-2016-8005 affects Intel Security McAfee Email Gateway versions prior to 7.6.404.
CVE-2016-8005 is a file extension filtering vulnerability that allows attackers to bypass security checks.
CVE-2016-8005 exploits the system by using a null byte in the filename extension of an email attachment, allowing forged filenames.