Feature Bypass
Sender: [EMAIL PROTECTED]
Precedence: bulk
Reply-To: [email protected]

(This message had word in it that many have filtered and
wouldn't have seen the post, so I changed the word).


TITLE:
ZoneAlarm Personal Firewall Program Control Feature
Bypass

SECUNIA ADVISORY ID:
SA17450

VERIFY ADVISORY:
http://secunia.com/advisories/17450/

CRITICAL:
Not critical

IMPACT:
Security Bypass

WHERE:
Local system

SOFTWARE:
ZoneAlarm Anti-Spyware 6.x
http://secunia.com/product/6073/
ZoneAlarm Antivirus 6.x
http://secunia.com/product/6074/
ZoneAlarm Internet Security Suite 6.x
http://secunia.com/product/6072/
ZoneAlarm Pro 6.x
http://secunia.com/product/6071/

DESCRIPTION:
A weakness in various ZoneAlarm products, which can be
exploited to bypass security features provided by the
product.

The weakness is caused due to the Program Control
feature failing to correctly identify and stop processes
that use the Internet Explorer browser to make outgoing
connections via the "ShowHTMLDialog()" API in
MSHTML.DLL. This may be exploited by malware to send
potentially sensitive information out from an affected
system.

The weakness has been confirmed in ZoneAlarm Pro 6.0.667
and reported in the following products:

* ZoneAlarm Pro 6.0.x

* ZoneAlarm Internet Security Suite 6.0.x

* ZoneAlarm Anti-Spyware with Firewall 6.1.x

* ZoneAlarm Antivirus with Firewall 6.0.x

Note: The free version of ZoneAlarm Firewall does not
support the "Advanced Program Control" feature, and
hence, does not prevent such bypass techniques.

Secunia does not normally regard this kind of security
bypass in personal firewalls as a vulnerability.
However, Secunia has decided to write about this
particular issue because Zone Labs is m*ark*eting the
product as being able to stop this kind of attack via
the "Advanced Program Control" functionality.

SOLUTION:
Do not run untrusted programs.

ORIGINAL ADVISORY:
http://www.hackingspirits.com/vuln-rnd/vuln-rnd.html


--
No virus found in this incoming message.
Checked by AVG Free Edition.
Version: 7.1.362 / Virus Database: 267.12.8/166 -
Release Date: 11/10/2005
 

-- 
No virus found in this outgoing message.
Checked by AVG Free Edition.
Version: 7.1.362 / Virus Database: 267.12.8/166 -
Release Date: 11/10/2005
============= PCWorks Mailing List =================
Don't see your post? Check our posting guidelines &
make sure you've followed proper posting procedures,
http://pcworkers.com/rules.htm
Contact list owner <[EMAIL PROTECTED]>
Unsubscribing and other changes: http://pcworkers.com
=====================================================

Reply via email to