7.5
CVSSv2

CVE-2002-0637

Published: 11/07/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

InterScan VirusWall 3.52 build 1462 allows remote malicious users to bypass virus protection via e-mail messages with headers that violate RFC specifications by having (or missing) space characters in unexpected places (aka "space gap"), such as (1) Content-Type :", (2) "Content-Transfer-Encoding :", (3) no space before a boundary declaration, or (4) "boundary= ", which is processed by Outlook Express.

Vulnerable Product Search on Vulmon Subscribe to Product

trend micro interscan viruswall 3.52

Exploits

source: wwwsecurityfocuscom/bid/5259/info A vulnerability has been reported in certain VirusWall versions Reportedly, it is possible to bypass the scanning mechanism of VirusWall by adding extraneous spaces in certain email HTTP header fields A malicious email server may add extraneous whitespace in certain email headers This would ca ...