Vulnerability CVE-2002-1121


Published: 2002-09-24   Modified: 2012-02-12

Description:
SMTP content filter engines, including (1) GFI MailSecurity for Exchange/SMTP before 7.2, (2) InterScan VirusWall before 3.52 build 1494, (3) the default configuration of MIMEDefang before 2.21, and possibly other products, do not detect fragmented emails as defined in RFC2046 ("Message Fragmentation and Reassembly") and supported in such products as Outlook Express, which allows remote attackers to bypass content filtering, including virus checking, via fragmented emails of the message/partial content type.

Vendor: GFI
Product: Mailsecurity 
Version: 7.2;
Vendor: Network associates
Product: Webshield smtp 
Version:
4.5.74.0
4.5.44
4.5
4.0.5
Vendor: Trend micro
Product: Interscan viruswall 
Version:
3.52
3.51
3.5
Vendor: Roaring penguin
Product: Mimedefang 
Version: 2.20; 2.14;
Product: Canit 
Version: 1.2;

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial

 References:
http://archives.neohapsis.com/archives/bugtraq/2002-09/0134.html
http://archives.neohapsis.com/archives/bugtraq/2002-09/0135.html
http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0113.html
http://marc.info/?l=bugtraq&m=103184267105132&w=2
http://marc.info/?l=bugtraq&m=103184501408453&w=2
http://www.iss.net/security_center/static/10088.php
http://www.kb.cert.org/vuls/id/836088
http://www.securiteam.com/securitynews/5YP0A0K8CM.html
http://www.securityfocus.com/bid/5696

Related CVE
CVE-2015-5957
Buffer overflow in the DumpSysVar function in var.c in Remind before 3.1.15 allows attackers to have unspecified impact via a long name.
CVE-2007-0884
Buffer overflow in Roaring Penguin MIMEDefang 2.59 and 2.60 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unspecified vectors.
CVE-2004-1098
MIMEDefang in MIME-tools 5.414 allows remote attackers to bypass virus scanning capabilities via an e-mail attachment with a virus that contains an empty boundary string in the Content-Type header.
CVE-2004-0564
Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its design, allows local users to overwrite arbitrary files. NOTE: the developer has publicly disputed the claim that this is a vulnerability because pppoe "i...
CVE-2001-0026
rp-pppoe PPPoE client allows remote attackers to cause a denial of service via the Clamp MSS option and a TCP packet with a zero-length TCP option.

Copyright 2019, cxsecurity.com

 

Back to Top