Clearswift MailSweeper附录文件名验证漏洞

漏洞信息详情

Clearswift MailSweeper附录文件名验证漏洞

漏洞简介

Clearswift MAILsweeper 4.0 到4.3.7版本存在漏洞。远程攻击者借助包含“multiple extensions combined with large blocks of white space”的文件附录绕过滤波。

漏洞公告

The vendor has released fixes to address this issue. A patch available to upgrade the system to 4.3.8 can only be applied to the 4.3.7 release of the software. More information is available from the vendor, and also the referenced bug report link.
Clearswift MailSweeper 4.0

Clearswift MailSweeper 4.1

Clearswift MailSweeper 4.2

Clearswift MailSweeper 4.3

Clearswift MailSweeper 4.3.3

Clearswift MailSweeper 4.3.4

Clearswift MailSweeper 4.3.5

Clearswift MailSweeper 4.3.6 SP1

Clearswift MailSweeper 4.3.6

Clearswift MailSweeper 4.3.7

参考网址

来源: BID
名称: 7568
链接:http://www.securityfocus.com/bid/7568

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享