Symantec Brightmail Anti-spam Unauthorized Message Disclosure Vulnerability
BID:10657
Info
Symantec Brightmail Anti-spam Unauthorized Message Disclosure Vulnerability
| Bugtraq ID: | 10657 |
| Class: | Access Validation Error |
| CVE: |
CVE-2004-0671 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | Discovery is credited to Thomas Springer. |
| Vulnerable: |
Symantec Brightmail Anti-Spam 6.0 |
| Not Vulnerable: | |
Discussion
Symantec Brightmail Anti-spam Unauthorized Message Disclosure Vulnerability
Symantec Brightmail anti-spam is reported prone to an unauthorized message disclosure vulnerability.
This issue exists in the Brightmail anti-spam control center. Due to improper access validation a remote attacker can read users' filtered email.
Symantec Brightmail anti-spam 6.0 is reported prone to this issue, however, other versions may be affected as well.
Symantec Brightmail anti-spam is reported prone to an unauthorized message disclosure vulnerability.
This issue exists in the Brightmail anti-spam control center. Due to improper access validation a remote attacker can read users' filtered email.
Symantec Brightmail anti-spam 6.0 is reported prone to this issue, however, other versions may be affected as well.
Exploit / POC
Symantec Brightmail Anti-spam Unauthorized Message Disclosure Vulnerability
No exploit is required.
The following proof of concept is available:
/brightmail/quarantine/viewMsgDetails.do?id=QMsgView-[some-value]
No exploit is required.
The following proof of concept is available:
/brightmail/quarantine/viewMsgDetails.do?id=QMsgView-[some-value]
Solution / Fix
Symantec Brightmail Anti-spam Unauthorized Message Disclosure Vulnerability
Solution:
Symantec has acknowledged the presence of this issue in Brightmail Anti-Spam 6.0. A fix is available for authorized customers through the support download site. To obtain the fix, please see the support download page in Web references below.
Solution:
Symantec has acknowledged the presence of this issue in Brightmail Anti-Spam 6.0. A fix is available for authorized customers through the support download site. To obtain the fix, please see the support download page in Web references below.
References
Symantec Brightmail Anti-spam Unauthorized Message Disclosure Vulnerability
References:
References:
- Brightmail Homepage (Symantec)
- Brightmail Support (Symantec)
- Ref: http://www.securityfocus.com/archive/1/367866, Jul 1 2004 1:19PM (Sym Security
)