MDaemon Input Validation Hole in Attachment Quarantine Feature Lets Remote Users Write Files to Arbitrary Locations
|
|
SecurityTracker Alert ID: 1014589
|
|
SecurityTracker URL: http://securitytracker.com/id?1014589
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Jul 28 2005
|
Impact: Modification of system information, Modification of user information, User access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Secunia Research
|
Version(s): prior to 8.1.0; Tested on 8.0.4.
|
Description: A vulnerability was reported in MDaemon. A remote user can write files to arbitrary directories on the target system.
The content filter does not properly validate user-supplied input. A remote user can send an e-mail message with a malicious attachment
that contains a specially crafted filename. If the attachment quarantine feature is enabled, the attachment will be written to
an arbitrary location instead of the normal quarantine directory.
A filename with directory traversal characters '../' can be
used to trigger this vulnerability.
Tan Chew Keong of Secunia Research discovered this vulnerability.
|
Impact: A remote user can write a file to an arbitrary directory on the target system. This can allow the remote user to obtain access on the target system.
|
Solution: The vendor has issued a fixed version (8.1.0).
|
Vendor URL: files.altn.com/MDaemon/Release/RelNotes_en.txt (Links to External Site)
|
Cause: Access control error, Input validation error
|
Underlying OS: Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Wed, 27 Jul 2005 23:03:19 -0400
Subject: http://secunia.com/advisories/16173/
|
http://secunia.com/advisories/16173/
http://files.altn.com/MDaemon/Release/RelNotes_en.txt
|
|