CVE-2004-1098 describes a vulnerability in MIMEDefang, part of MIME-tools 5.414, which allows remote attackers to bypass virus scanning. This bypass is achieved by sending an email attachment containing a virus with an empty boundary string in its Content-Type header, affecting products from vendors like Mandrakesoft, Roaring Penguin, and SUSE. The vulnerability has a CVSS score of 7.5, indicating high severity with a network attack vector and low attack complexity, potentially leading to partial confidentiality, integrity, and availability impacts. Its FAUCET Risk Score is 85/100, further highlighting its significant risk. While there is no evidence of active exploitation (KEV: No) and no known public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered considerable community discussion with 10 mentions, suggesting awareness and potential interest among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4CPE matchmatch criteria | cpe:2.3:a:roaring_penguin:mimedefang:2.4:*:*:*:*:*:*:* | ||
2.14CPE matchmatch criteria | cpe:2.3:a:roaring_penguin:mimedefang:2.14:*:*:*:*:*:*:* | ||
2.20CPE matchmatch criteria | cpe:2.3:a:roaring_penguin:mimedefang:2.20:*:*:*:*:*:*:* | ||
2.21CPE matchmatch criteria | cpe:2.3:a:roaring_penguin:mimedefang:2.21:*:*:*:*:*:*:* | ||
2.38CPE matchmatch criteria | cpe:2.3:a:roaring_penguin:mimedefang:2.38:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.