Vulnerability Description
InterScan VirusWall 3.52 build 1462 allows remote attackers to bypass virus protection via e-mail messages with headers that violate RFC specifications by having (or missing) space characters in unexpected places (aka "space gap"), such as (1) Content-Type :", (2) "Content-Transfer-Encoding :", (3) no space before a boundary declaration, or (4) "boundary= ", which is processed by Outlook Express.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trend Micro | Interscan Viruswall | 3.52 |
References
- http://www.iss.net/security_center/static/9464.php
- http://www.securiteam.com/securitynews/5KP000A7QE.htmlPatchVendor Advisory
- http://www.iss.net/security_center/static/9464.php
- http://www.securiteam.com/securitynews/5KP000A7QE.htmlPatchVendor Advisory
FAQ
What is CVE-2002-0637?
CVE-2002-0637 is a vulnerability with a CVSS score of 7.5 (HIGH). InterScan VirusWall 3.52 build 1462 allows remote attackers to bypass virus protection via e-mail messages with headers that violate RFC specifications by having (or missing) space characters in unexp...
How severe is CVE-2002-0637?
CVE-2002-0637 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-0637?
Check the references section above for vendor advisories and patch information. Affected products include: Trend Micro Interscan Viruswall.