Overview
Email anti-virus scanners and content filters from multiple vendors do not adequately check messages containing "message/partial" MIME entities (RFC 2046). As a result, viruses, malicious code, or other restricted content may not be detected.
Description
Section 5.2.2 of RFC 2046 defines the "message/partial" Multipurpose Internet Mail Extensions (MIME) type: 5.2.2. Partial Subtype |
Impact
Email anti-virus and content filters may not detect viruses, malicious code, or other restricted content that is sent as "message/partial" MIME parts in multiple email messages. Such messages may be automatically reassembled by MUAs, thus delivering the virus, malicious code, or restricted content to users. |
Solution
|
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.securiteam.com/securitynews/5YP0A0K8CM.html
- http://online.securityfocus.com/bid/5696
- http://online.securityfocus.com/archive/1/291993
- http://www.iss.net/security_center/static/10088.php
Acknowledgements
The CERT/CC thanks Noam Rathaus of Beyond-Security SecuriTeam for reporting this vulnerability, and Menashe Eliezer of Finjan Software for information used in this document.
This document was written by Art Manion.
Other Information
CVE IDs: | CVE-2002-1121 |
Severity Metric: | 1.80 |
Date Public: | 2002-09-12 |
Date First Published: | 2002-09-13 |
Date Last Updated: | 2002-09-18 22:14 UTC |
Document Revision: | 32 |