CVE-2002-0637
Trend Micro Interscan VirusWall for Windows NT 3.52 - Space Gap Scan Bypass
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
InterScan VirusWall 3.52 build 1462 allows remote attackers to bypass virus protection via e-mail messages with headers that violate RFC specifications by having (or missing) space characters in unexpected places (aka "space gap"), such as (1) Content-Type :", (2) "Content-Transfer-Encoding :", (3) no space before a boundary declaration, or (4) "boundary= ", which is processed by Outlook Express.
Interscan VirusWall build 1462 permite a atacantes remotos evadir la protección mediante mensajes de correo con cabeceras que no cumplen la especificaciónes RFC por tener (o faltarle) caractéres de espacio en lugares inesperados (también conocido como "space gap"); como en:
"Content-Type :"
"Content-Transfer-Encoding :"
Sin espacio antes de una declaración de límites, o
"boundary= ", que es procesado por Outlook Express.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2002-06-25 CVE Reserved
- 2002-07-04 CVE Published
- 2002-07-18 First Exploit
- 2023-03-07 EPSS Updated
- 2024-08-08 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.iss.net/security_center/static/9464.php | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/21625 | 2002-07-18 |
URL | Date | SRC |
---|---|---|
http://www.securiteam.com/securitynews/5KP000A7QE.html | 2008-09-05 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Trend Micro Search vendor "Trend Micro" | Interscan Viruswall Search vendor "Trend Micro" for product "Interscan Viruswall" | 3.52 Search vendor "Trend Micro" for product "Interscan Viruswall" and version "3.52" | - |
Affected
|