Critical ZoneAlarm Flaw
Thursday February 19, 2004
Zone Labs ZoneAlarm 4 products, including ZoneAlarm Pro 4.x, ZoneAlarm Plus 4.x, ZoneAlarm 4.x and Zone Labs Integrity 4.x, are vulnerable to exploitation due to a potential buffer overflow in the SMTP (Simple Mail Transfer Protocol) processing. A successful attack against this flaw may allow the attacker to shut down the ZoneAlarm firewall, escalate privileges or execute arbitrary code on the target system. Any users of ZoneAlarm 4.x products are urged to update their software as soon as possible. For more information you can see this Secunia Advisory or the Zone Labs Security Advisory.
