Zone Labs IMsecure Active Link Filtering Function Can Be Bypassed
|
|
SecurityTracker Alert ID: 1011584
|
|
SecurityTracker URL: http://securitytracker.com/id?1011584
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Updated: Nov 11 2004
|
Original Entry Date: Oct 10 2004
|
Impact: Modification of user information
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): prior to 1.5
|
Description: A vulnerability was reported in IMsecure. A remote user can create a link that will bypass Active Link filtering.
Kurczaba Associates announced that there is a vulnerability in the filtering capability of IMsecure. In some situations, a remote
user can create a specially encoded URL that will bypass the Active Link filtering function in IMsecure and IMsecure Pro.
A demonstration
exploit URL is provided:
http://[site]/somefile.e%78e
|
Impact: A remote user can create a link that will bypass Active Link filtering.
|
Solution: The vendor has issued a fixed version (1.5).
For IMsecure Pro update:
http://download.zonelabs.com/bin/updates/imsp/imsp1539AEN9903.html
For
IMsecure Update:
http://download.zonelabs.com/bin/updates/ims/ims1539AEN9903.html
|
Vendor URL: www.zonelabs.com/store/content/catalog/products/imsp/imsp_details.jsp?lid=ho_imsecurepro (Links to External Site)
|
Cause: Input validation error
|
Underlying OS: Windows (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Sat, 9 Oct 2004 20:51:32 -0400
Subject: [none]
|
> Zone Labs IMsecure Filter Vulnerability (Not disclosed yet)
Kurczaba Associates announced that there is a vulnerability in IMsecure. The impact
was not disclosed.
The flaw resides in the filtering capability. No further details were provided.
Vendor URL: http://www.zonelabs.com/store/content/catalog/products/imsp/imsp_details.jsp?lid=ho_imsec urepro
|
|