MidnightBSD

Advisories for paul_l_daniels

CVE-2002-0198 HIGH

Buffer overflow in plDaniels ripMime 1.2.6 and earlier, as used in other programs such as xamime and inflex, allows remote attackers to execute arbitrary code via an attachment in a long filename.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
paul_l_daniels inflex 1.0.10
paul_l_daniels ripmime 1.2.3
paul_l_daniels ripmime 1.2.0
paul_l_daniels ripmime 1.2.2
paul_l_daniels ripmime 1.2.4
paul_l_daniels ripmime 1.2.5
paul_l_daniels ripmime 1.2.6
paul_l_daniels ripmime 1.2.1
CVE-2003-1015 HIGH

Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use whitespace in an unusual fashion, which may be interpreted differently by mail clients.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
paul_l_daniels ripmime 1.3.2.3
paul_l_daniels ripmime 1.2.0
paul_l_daniels ripmime 1.2.4
f-secure internet_gatekeeper 6.32
f-secure internet_gatekeeper 6.3
clearswift mailsweeper 4.3.7
clearswift mailsweeper 4.3.8
paul_l_daniels ripmime 1.3.2.0
paul_l_daniels ripmime 1.3.2.2
clearswift mailsweeper 4.3.11
clearswift mailsweeper 4.3.13
f-secure internet_gatekeeper 6.4
paul_l_daniels ripmime 1.2.3
clearswift mailsweeper 4.3.15
clearswift mailsweeper 4.3.10
paul_l_daniels ripmime 1.2.2
paul_l_daniels ripmime 1.2.5
paul_l_daniels ripmime 1.2.7
clearswift mailsweeper 4.3.14
paul_l_daniels ripmime 1.2.6
paul_l_daniels ripmime 1.2.1
f-secure internet_gatekeeper 6.31
CVE-2003-1016 HIGH

Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use malformed quoting in MIME headers, parameters, and values, including (1) fields that should not be quoted, (2) duplicate quotes, or (3) missing leading or trailing quote characters, which may be interpreted differently by mail clients.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
paul_l_daniels ripmime 1.3.2.3
paul_l_daniels ripmime 1.2.0
paul_l_daniels ripmime 1.2.4
f-secure internet_gatekeeper 6.32
f-secure internet_gatekeeper 6.3
clearswift mailsweeper 4.3.7
clearswift mailsweeper 4.3.8
paul_l_daniels ripmime 1.3.2.0
paul_l_daniels ripmime 1.3.2.2
clearswift mailsweeper 4.3.11
clearswift mailsweeper 4.3.13
f-secure internet_gatekeeper 6.4
paul_l_daniels ripmime 1.2.3
clearswift mailsweeper 4.3.15
clearswift mailsweeper 4.3.10
paul_l_daniels ripmime 1.2.2
paul_l_daniels ripmime 1.2.5
paul_l_daniels ripmime 1.2.7
clearswift mailsweeper 4.3.14
paul_l_daniels ripmime 1.2.6
paul_l_daniels ripmime 1.2.1
f-secure internet_gatekeeper 6.31
CVE-2004-0051 HIGH

Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard but frequently supported Content-Transfer-Encoding values such as (1) uuencode, (2) mac-binhex40, and (3) yenc, which may be interpreted differently by mail clients.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
paul_l_daniels ripmime 1.3.2.3
paul_l_daniels ripmime 1.2.0
paul_l_daniels ripmime 1.2.4
f-secure internet_gatekeeper 6.32
f-secure internet_gatekeeper 6.3
clearswift mailsweeper 4.3.7
clearswift mailsweeper 4.3.8
paul_l_daniels ripmime 1.3.2.0
paul_l_daniels ripmime 1.3.2.2
clearswift mailsweeper 4.3.11
clearswift mailsweeper 4.3.13
f-secure internet_gatekeeper 6.4
paul_l_daniels ripmime 1.2.3
clearswift mailsweeper 4.3.15
clearswift mailsweeper 4.3.10
paul_l_daniels ripmime 1.2.2
paul_l_daniels ripmime 1.2.5
paul_l_daniels ripmime 1.2.7
clearswift mailsweeper 4.3.14
paul_l_daniels ripmime 1.2.6
paul_l_daniels ripmime 1.2.1
f-secure internet_gatekeeper 6.31
CVE-2004-0052 HIGH

Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard separator characters, or use standard separators incorrectly, within MIME headers, fields, parameters, or values, which may be interpreted differently by mail clients.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
paul_l_daniels ripmime 1.3.2.3
paul_l_daniels ripmime 1.2.0
paul_l_daniels ripmime 1.2.4
f-secure internet_gatekeeper 6.32
f-secure internet_gatekeeper 6.3
clearswift mailsweeper 4.3.7
clearswift mailsweeper 4.3.8
paul_l_daniels ripmime 1.3.2.0
paul_l_daniels ripmime 1.3.2.2
clearswift mailsweeper 4.3.11
clearswift mailsweeper 4.3.13
f-secure internet_gatekeeper 6.4
paul_l_daniels ripmime 1.2.3
clearswift mailsweeper 4.3.15
clearswift mailsweeper 4.3.10
paul_l_daniels ripmime 1.2.2
paul_l_daniels ripmime 1.2.5
paul_l_daniels ripmime 1.2.7
clearswift mailsweeper 4.3.14
paul_l_daniels ripmime 1.2.6
paul_l_daniels ripmime 1.2.1
f-secure internet_gatekeeper 6.31
CVE-2004-0053 HIGH

Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use fields that use RFC2047 encoding, which may be interpreted differently by mail clients.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
paul_l_daniels ripmime 1.3.2.3
paul_l_daniels ripmime 1.2.0
paul_l_daniels ripmime 1.2.4
f-secure internet_gatekeeper 6.32
f-secure internet_gatekeeper 6.3
clearswift mailsweeper 4.3.7
clearswift mailsweeper 4.3.8
paul_l_daniels ripmime 1.3.2.0
paul_l_daniels ripmime 1.3.2.2
clearswift mailsweeper 4.3.11
clearswift mailsweeper 4.3.13
f-secure internet_gatekeeper 6.4
paul_l_daniels ripmime 1.2.3
clearswift mailsweeper 4.3.15
clearswift mailsweeper 4.3.10
paul_l_daniels ripmime 1.2.2
paul_l_daniels ripmime 1.2.5
paul_l_daniels ripmime 1.2.7
clearswift mailsweeper 4.3.14
paul_l_daniels ripmime 1.2.6
paul_l_daniels ripmime 1.2.1
f-secure internet_gatekeeper 6.31
CVE-2004-0161 HIGH

Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use RFC2231 encoding, which may be interpreted differently by mail clients.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
paul_l_daniels ripmime 1.3.2.3
paul_l_daniels ripmime 1.2.0
paul_l_daniels ripmime 1.2.4
f-secure internet_gatekeeper 6.32
f-secure internet_gatekeeper 6.3
clearswift mailsweeper 4.3.7
clearswift mailsweeper 4.3.8
paul_l_daniels ripmime 1.3.2.0
paul_l_daniels ripmime 1.3.2.2
clearswift mailsweeper 4.3.11
clearswift mailsweeper 4.3.13
f-secure internet_gatekeeper 6.4
paul_l_daniels ripmime 1.2.3
clearswift mailsweeper 4.3.15
clearswift mailsweeper 4.3.10
paul_l_daniels ripmime 1.2.2
paul_l_daniels ripmime 1.2.5
paul_l_daniels ripmime 1.2.7
clearswift mailsweeper 4.3.14
paul_l_daniels ripmime 1.2.6
paul_l_daniels ripmime 1.2.1
f-secure internet_gatekeeper 6.31
CVE-2004-0162 HIGH

Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME encapsulation that uses RFC822 comment fields, which may be interpreted as other fields by mail clients.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
paul_l_daniels ripmime 1.3.2.3
paul_l_daniels ripmime 1.2.0
paul_l_daniels ripmime 1.2.4
f-secure internet_gatekeeper 6.32
f-secure internet_gatekeeper 6.3
clearswift mailsweeper 4.3.7
clearswift mailsweeper 4.3.8
paul_l_daniels ripmime 1.3.2.0
paul_l_daniels ripmime 1.3.2.2
clearswift mailsweeper 4.3.11
clearswift mailsweeper 4.3.13
f-secure internet_gatekeeper 6.4
paul_l_daniels ripmime 1.2.3
clearswift mailsweeper 4.3.15
clearswift mailsweeper 4.3.10
paul_l_daniels ripmime 1.2.2
paul_l_daniels ripmime 1.2.5
paul_l_daniels ripmime 1.2.7
clearswift mailsweeper 4.3.14
paul_l_daniels ripmime 1.2.6
paul_l_daniels ripmime 1.2.1
f-secure internet_gatekeeper 6.31
CVE-2004-0289 LOW

Buffer overflow in sdbscan in SignatureDB 0.1.1 allows local users to cause a denial of service (segmentation fault) via a database file that contains a large key parameter.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
paul_l_daniels signaturedb 0.1.1
CVE-2004-2619 HIGH

ripMIME 1.3.2.3 and earlier allows remote attackers to bypass e-mail protection via a base64 MIME encoded attachment containing invalid characters that are not properly extracted.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
paul_l_daniels ripmime 1.3.2.2
paul_l_daniels ripmime *
paul_l_daniels ripmime 1.2.3
paul_l_daniels ripmime 1.2.0
paul_l_daniels ripmime 1.2.2
paul_l_daniels ripmime 1.2.4
paul_l_daniels ripmime 1.2.5
paul_l_daniels ripmime 1.2.7
paul_l_daniels ripmime 1.2.6
paul_l_daniels ripmime 1.3.2.0
paul_l_daniels ripmime 1.2.1
CVE-2004-2620 MEDIUM

The MIMEH_read_headers function in ripMIME 1.3.1.0 does not properly handle trailing "\r" and "\n" characters in headers, which leads to a buffer underflow.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
paul_l_daniels ripmime 1.3.1.0