Symantec Brightmail AntiSpam Lets Remote Users Traverse the Directory
|
|
SecurityTracker Alert ID: 1016600
|
|
SecurityTracker URL: http://securitytracker.com/id?1016600
|
|
CVE Reference: CVE-2006-4013
, CVE-2006-4014
(Links to External Site)
|
Updated: Jun 8 2008
|
Original Entry Date: Jul 28 2006
|
Impact: Disclosure of system information, Disclosure of user information, Modification of system information, Modification of user information
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Symantec Advisory
|
Version(s): prior to 6.0.4
|
Description: A vulnerability was reported in Symantec Brightmail AntiSpam. A remote user can view or modify files on the target system.
The software does not properly validate user-supplied input in file names passed to the DATABLOB-GET/DATABLOB-SAVE requests. When
Brightmail AntiSpam is configured to recognize a Control Center connection from any computer, a remote user can send an invalid
post to cause the anti-spam service to crash. A remote user can also supply a specially crafted request containing directory traversal
characters to view or modify files on target system.
Symantec credits George A. Theall of Tenable Network Security, Inc. with
reporting this vulnerability.
|
Impact: A remote user can view or modify files on the target system.
|
Solution: Symantec has issued a fix and recommends that all users upgrade to Symantec Mail Security (SMS) for SMTP 5.0, which is not vulnerable.
For users that cannot upgrade to SMS for SMTP 5.0, a fixed version (6.0.4) of Brightmail is available.
The Symantec advisory
is available at:
http://securityresponse.symantec.com/avcenter/security/Content/2006.07.27.html
|
Vendor URL: securityresponse.symantec.com/avcenter/security/Content/2006.07.27.html (Links to External Site)
|
Cause: Input validation error
|
Underlying OS: Linux (Red Hat Enterprise), UNIX (Solaris - SunOS), Windows (2000), Windows (2003)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Fri, 28 Jul 2006 00:44:29 -0400
Subject: Symantec Brightmail AntiSpam Multiple Vulnerabilities
|
http://securityresponse.symantec.com/avcenter/security/Content/2006.07.27.html
|
|