This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Clearswift First view 2003-12-31
Product Mailsweeper Last view 2004-12-31
Version 4.3.5 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:clearswift:mailsweeper

Activity : Overall

Related : CVE

  Date Alert Description
5 2004-12-31 CVE-2004-2328

Clearswift MAILsweeper for SMTP before 4.3_13 allows remote attackers to cause a denial of service (infinite loop) via an e-mail with a crafted RAR archive attached.

7.5 2004-09-28 CVE-2003-0930

Clearswift MAILsweeper before 4.3.15 does not properly detect filenames in BinHex (HQX) encoded files, which allows remote attackers to bypass intended policy.

7.5 2004-09-28 CVE-2003-0929

Clearswift MAILsweeper before 4.3.15 does not properly detect and filter ZIP 6.0 encoded files, which allows remote attackers to bypass intended policy.

7.5 2004-09-28 CVE-2003-0928

Clearswift MAILsweeper before 4.3.15 does not properly detect and filter RAR 3.20 encoded files, which allows remote attackers to bypass intended policy.

6.4 2004-08-18 CVE-2004-0235

Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path").

10 2004-08-18 CVE-2004-0234

Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive.

5 2003-12-31 CVE-2003-1485

Clearswift MAILsweeper 4.0 through 4.3.7 allows remote attackers to bypass filtering via a file attachment that contains "multiple extensions combined with large blocks of white space."

7.5 2003-12-31 CVE-2003-1154

MAILsweeper for SMTP 4.3 allows remote attackers to bypass virus protection via a mail message with a malformed zip attachment, as exploited by certain MIMAIL virus variants.

CWE : Common Weakness Enumeration

%idName
50% (1) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
50% (1) CWE-20 Improper Input Validation

Open Source Vulnerability Database (OSVDB)

id Description
60265 Clearswift MAILsweeper Multiple Extension File Attachment Filter Bypass
8844 MAILsweeper for SMTP Attachment Blocking Bypass
5755 LHA Arbitrary File Access
5753 LHA get_header() Function File / Directory Name Handling Overflow
3742 MAILsweeper for SMTP Crafted RAR Attachment DoS
2772 MAILsweeper Malformed Zip Archive Virus Detection Bypass

ExploitDB Exploits

id Description
24067 LHA 1.x Buffer Overflow/Directory Traversal Vulnerabilities

OpenVAS Exploits

id Description
2008-09-24 Name : Gentoo Security Advisory GLSA 200405-02 (lha)
File : nvt/glsa_200405_02.nasl
2008-09-04 Name : FreeBSD Ports: lha
File : nvt/freebsd_lha0.nasl
2008-01-17 Name : Debian Security Advisory DSA 515-1 (lha)
File : nvt/deb_515_1.nasl
0000-00-00 Name : Slackware Advisory SSA:2004-125-01 lha update in bin package
File : nvt/esoft_slk_ssa_2004_125_01.nasl

Snort® IPS/IDS

Date Description
2014-01-10 F-Secure Anti-Virus LHA processing buffer overflow attempt
RuleID : 15966 - Type : FILE-OTHER - Revision : 9

Nessus® Vulnerability Scanner

id Description
2009-04-23 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_a2ffb6279c5311d893660020ed76ef5a.nasl - Type: ACT_GATHER_INFO
2005-07-13 Name: The remote Slackware host is missing a security update.
File: Slackware_SSA_2004-125-01.nasl - Type: ACT_GATHER_INFO
2004-09-29 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-515.nasl - Type: ACT_GATHER_INFO
2004-08-30 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-200405-02.nasl - Type: ACT_GATHER_INFO
2004-08-23 Name: The remote SMTP server has a security bypass vulnerability.
File: mailsweeper_archive_filtering.nasl - Type: ACT_GATHER_INFO
2004-07-23 Name: The remote Fedora Core host is missing a security update.
File: fedora_2004-119.nasl - Type: ACT_GATHER_INFO
2004-07-06 Name: The remote Red Hat host is missing a security update.
File: redhat-RHSA-2004-178.nasl - Type: ACT_GATHER_INFO