Description
The pop3 Proxy in Astaro Security Gateway (ASG) 7 does not perform virus scanning of attachments that exceed the maximum attachment size, and passes these attachments, which allows remote attackers to bypass this scanning via a large attachment.
Affected products
- astaro / security_gateway7.0 – 7.0
References
- MISChttp://securityreason.com/securityalert/2981
- MISChttp://www.securityfocus.com/archive/1/477120/100/0/threaded
- MISChttp://www.securityfocus.com/archive/1/475642/100/0/threaded
- MISChttp://www.securitytracker.com/id?1018543
- MISChttp://www.hescominsoon.com/archives/773
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/35827