Clearswift MAILsweeper for SMTP 4.3.6 SP1 does not execute custom "on strip unsuccessful" hooks, which allows remote attackers to bypass e-mail attachment filtering policies via an attachment that MAILsweeper can detect but not remove.
https://exchange.xforce.ibmcloud.com/vulnerabilities/11745
http://www.securityfocus.com/bid/7226
http://www.mimesweeper.com/download/bin/Patches/MAILsweeper_Patches_301_ReadMe.htm