CVE-2014-3381
N/A
N/A
Summary
The ZIP inspection engine in Cisco AsyncOS 8.5 and earlier on the Cisco Email Security Appliance (ESA) does not properly analyze ZIP archives, which allows remote attackers to bypass malware filtering via a crafted archive, aka Bug ID CSCup07934.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3381
- http://tools.cisco.com/security/center/viewAlert.x?alertId=36062
References
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3381
- http://tools.cisco.com/security/center/viewAlert.x?alertId=36062
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.