Input validation error in Cisco AsyncOS for Cisco Email Security Appliance - CVE-2020-3134
Published: January 27, 2020
Cisco AsyncOS for Cisco Email Security Appliance
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper validation of zip files in the zip decompression engine. A remote attacker can send an email message with a crafted zip-compressed attachment and trigger a restart of the content-scanning process, causing a temporary denial of service condition.