|
|
Info |
Last Modified |
| 5 months ago |
|
|
|
|
Description |
According to the advisory, ZoneAlarm Pro contains a flaw that may allow a remote attacker to bypass the 'Mobile Code' filter. The 'Mobile Code' blocking feature filters malicious Web objects and any 'application/*' MIME type, but does not filter SSL content. A remote attacker could create a malicious SSL Web page and bypass the Mobile Code filter.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Cryptographic
Impact:
Loss of Confidentiality
Exploit:
Exploit Unknown
OSVDB:
Myth/Fake
|
|
Solution |
According to the vendor, "ZoneAlarm Pro, Security Suite and Integrity products which employ Mobile Code Protection/ID Lock features do not inspect encrypted traffic. If mobile code is downloaded via a Secure Sockets Layer (SSL) session, it will not be inspected by these products. This is by design and mandated by the SSL Protocol specification."
|
|
Products |
|
ZoneAlarm Pro
 |
5.0.590.015 |
|
|
|
|
Credit |
- Paul Kurczaba - Kurczaba Associates
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|