CVE-2002-1121
SMTP content filter engines, including (1) GFI MailSecurity for Exchange/SMTP before 7.2, (2) InterScan VirusWall before 3.52 build 1494, (3) the default configuration of MIMEDefang before 2.21, and possibly other products, do not detect fragmented…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.67%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SMTP content filter engines, including (1) GFI MailSecurity for Exchange/SMTP before 7.2, (2) InterScan VirusWall before 3.52 build 1494, (3) the default configuration of MIMEDefang before 2.21, and possibly other products, do not detect fragmented emails as defined in RFC2046 ("Message Fragmentation and Reassembly") and supported in such products as Outlook Express, which allows remote attackers to bypass content filtering, including virus checking, via fragmented emails of the message/partial content type.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 6.67% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- gfi/mailsecurity · network associates/webshield smtp · roaring penguin/canit · roaring penguin/mimedefang · trend micro/interscan viruswall
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2002-09/0134.html
- http://archives.neohapsis.com/archives/bugtraq/2002-09/0135.html
- http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0113.htmlVendor Advisory
- http://marc.info/?l=bugtraq&m=103184267105132&w=2
- http://marc.info/?l=bugtraq&m=103184501408453&w=2
- http://www.iss.net/security_center/static/10088.phpVendor Advisory
- http://www.kb.cert.org/vuls/id/836088US Government Resource
- http://www.securiteam.com/securitynews/5YP0A0K8CM.html
- http://www.securityfocus.com/bid/5696
- http://archives.neohapsis.com/archives/bugtraq/2002-09/0134.html
- http://archives.neohapsis.com/archives/bugtraq/2002-09/0135.html
- http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0113.htmlVendor Advisory
- http://marc.info/?l=bugtraq&m=103184267105132&w=2
- http://marc.info/?l=bugtraq&m=103184501408453&w=2
- http://www.iss.net/security_center/static/10088.phpVendor Advisory
- http://www.kb.cert.org/vuls/id/836088US Government Resource
- http://www.securiteam.com/securitynews/5YP0A0K8CM.html
- http://www.securityfocus.com/bid/5696
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.