Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Please tell me why send a email with BMP image will judged to be a threat?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Please tell me why send a email with BMP image will judged to be a threat?

L0 Member

Please tell me why send a email with BMP image will judged to be a threat?

The firewall will show up a threaten sentence, during the sending job..

Please help me here. Thank you.

 

Threat Details: Name: IBM Lotus Domino BMP Parsing Integer Overflow Vulnerability

ID: 38197

Description

IBM Lotus Domino is prone to an integer overflow vulnerability while parsing certain crafted BMP files. The vulnerability is due to the lack of proper checks on bounds checking on dimensions in a BMP file, which is used for buffer allocation. An attacker could exploit the vulnerability by sending a crafted BMP files in an e-mail. A successful attack could lead to remote code execution with the privileges of the server.

2 REPLIES 2

L3 Networker

Because it matches the Vulnerability signature. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1902

Dealing with false positives is pretty normal - everything will not magically work out of box. First two options tod eal with it on top of my mind are:

1. Change the default action for the whole role if you feel like Lotus Domino vulnerabilities are not your concern (you don't have that in your network, etc.).

2. Create Security rule matching traffic from your server and with different Vulnerability profile assigned which will be created not to trigger this specific vulnerability. 

 

Cyber Elite
Cyber Elite

Your BMP image is matching the threat signature. You can simply change the default action if this isn't something that you are worried about or you can disable the threat id in general if you don't have any Lotos in your infrastructure that would be affected by this vulnerability. 

  • 2455 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!