The SMTP ALG in Clavister CorePlus before 8.80.04, and 8.81.00, does not properly parse SMTP commands in certain circumstances, which allows remote attackers to bypass address blacklists.Referenceshttp://www.clavister.com/releasenotes/CorePlus_Release_Notes_8_80_04.pdfhttp://www.clavister.com/releasenotes/CorePlus_Release_Notes_8_81_01.pdfhttp://osvdb.org/37974http://secunia.com/advisories/25957https://exchange.xforce.ibmcloud.com/vulnerabilities/35371