Zone Labs ZoneAlarm MailSafe Bypass Vulnerability

Due to a flaw in the handling of long filenames, it is possible for a user to bypass the MailSafe feature of ZoneAlarm. If an attachment is composed with an unusually long filename along with a prohibited file extension, ZoneAlarm will treat the illicit file as one of a trusted type.


 

Privacy Statement
Copyright 2010, SecurityFocus