Please tell me why send a email with BMP image will judged to be a threat?
The firewall will show up a threaten sentence, during the sending job..
Please help me here. Thank you.
Threat Details： Name: IBM Lotus Domino BMP Parsing Integer Overflow Vulnerability
IBM Lotus Domino is prone to an integer overflow vulnerability while parsing certain crafted BMP files. The vulnerability is due to the lack of proper checks on bounds checking on dimensions in a BMP file, which is used for buffer allocation. An attacker could exploit the vulnerability by sending a crafted BMP files in an e-mail. A successful attack could lead to remote code execution with the privileges of the server.
Because it matches the Vulnerability signature. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1902
Dealing with false positives is pretty normal - everything will not magically work out of box. First two options tod eal with it on top of my mind are:
1. Change the default action for the whole role if you feel like Lotus Domino vulnerabilities are not your concern (you don't have that in your network, etc.).
2. Create Security rule matching traffic from your server and with different Vulnerability profile assigned which will be created not to trigger this specific vulnerability.
Your BMP image is matching the threat signature. You can simply change the default action if this isn't something that you are worried about or you can disable the threat id in general if you don't have any Lotos in your infrastructure that would be affected by this vulnerability.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!