<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Please tell me why send a email with BMP image will judged to be a threat? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/please-tell-me-why-send-a-email-with-bmp-image-will-judged-to-be/m-p/98770#M44155</link>
    <description>&lt;P&gt;Your BMP image is matching the threat signature. You can simply change the default action if this isn't something that you are worried about or you can disable the threat id in general if you don't have any Lotos in your infrastructure that would be affected by this vulnerability.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Jul 2016 13:42:07 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2016-07-20T13:42:07Z</dc:date>
    <item>
      <title>Please tell me why send a email with BMP image will judged to be a threat?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-tell-me-why-send-a-email-with-bmp-image-will-judged-to-be/m-p/98533#M44144</link>
      <description>&lt;P&gt;Please tell me why send a email with BMP image will judged to be a threat?&lt;/P&gt;&lt;P&gt;The firewall will show up a threaten sentence, during the sending job..&lt;/P&gt;&lt;P&gt;Please help me here. Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Threat Details： Name: IBM Lotus Domino BMP Parsing Integer Overflow Vulnerability&lt;/P&gt;&lt;P&gt;ID: 38197&lt;/P&gt;&lt;P&gt;Description&lt;/P&gt;&lt;P&gt;IBM Lotus Domino is prone to an integer overflow vulnerability while parsing certain crafted BMP files. The vulnerability is due to the lack of proper checks on bounds checking on dimensions in a BMP file, which is used for buffer allocation. An attacker could exploit the vulnerability by sending a crafted BMP files in an e-mail. A successful attack could lead to remote code execution with the privileges of the server.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2016 05:03:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-tell-me-why-send-a-email-with-bmp-image-will-judged-to-be/m-p/98533#M44144</guid>
      <dc:creator>PaadminAVI</dc:creator>
      <dc:date>2016-07-20T05:03:30Z</dc:date>
    </item>
    <item>
      <title>Re: Please tell me why send a email with BMP image will judged to be a threat?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-tell-me-why-send-a-email-with-bmp-image-will-judged-to-be/m-p/98690#M44148</link>
      <description>&lt;P&gt;Because it matches the Vulnerability signature.&amp;nbsp;&lt;A href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1902" target="_blank"&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1902&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Dealing with false positives is pretty normal - everything will not magically work out of box. First two options tod eal with it on top of my mind are:&lt;/P&gt;&lt;P&gt;1. Change the default action for the whole role if you feel like Lotus Domino vulnerabilities are not your concern (you don't have that in your network, etc.).&lt;/P&gt;&lt;P&gt;2. Create Security rule matching traffic from your server and with different Vulnerability profile assigned which will be created not to trigger this specific vulnerability.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2016 09:23:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-tell-me-why-send-a-email-with-bmp-image-will-judged-to-be/m-p/98690#M44148</guid>
      <dc:creator>nikoo</dc:creator>
      <dc:date>2016-07-20T09:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: Please tell me why send a email with BMP image will judged to be a threat?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-tell-me-why-send-a-email-with-bmp-image-will-judged-to-be/m-p/98770#M44155</link>
      <description>&lt;P&gt;Your BMP image is matching the threat signature. You can simply change the default action if this isn't something that you are worried about or you can disable the threat id in general if you don't have any Lotos in your infrastructure that would be affected by this vulnerability.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2016 13:42:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-tell-me-why-send-a-email-with-bmp-image-will-judged-to-be/m-p/98770#M44155</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-07-20T13:42:07Z</dc:date>
    </item>
  </channel>
</rss>

