Vulnerability CVE-2009-1240


Published: 2009-04-03   Modified: 2012-02-13

Description:
Unspecified vulnerability in the IBM Proventia engine 4.9.0.0.44 20081231, as used in IBM Proventia Network Mail Security System, Network Mail Security System Virtual Appliance, Desktop Endpoint Security, Network Multi-Function Security (MFS), and possibly other products, allows remote attackers to bypass detection of malware via a modified RAR archive.

See advisories in our WLB2 database:
Topic
Author
Date
High
IBM Proventia - Generic bypass
Thierry Zoller
08.04.2009

Type:

CWE-noinfo

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
IBM -> Proventia desktop endpoint security 
IBM -> Proventia network mail security system 
IBM -> Network multi-function security 
IBM -> Proventia network mail security system virtual appliance 

 References:
http://blog.zoller.lu/2009/04/ibm-proventia-evasion-limited-details.html
http://iss.custhelp.com/cgi-bin/iss.cfg/php/enduser/std_adp.php?p_faqid=5417
http://www.securityfocus.com/archive/1/502369/100/0/threaded
http://www.securityfocus.com/archive/1/504987/100/0/threaded
http://www.securityfocus.com/archive/1/504992/100/0/threaded
http://www.securityfocus.com/archive/1/504995/100/0/threaded
http://www.securityfocus.com/bid/34345

Copyright 2024, cxsecurity.com

 

Back to Top