Symantec Brightmail AntiSpam Remote Information Disclosure Vulnerability
BID:13828
Info
Symantec Brightmail AntiSpam Remote Information Disclosure Vulnerability
| Bugtraq ID: | 13828 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 01 2005 12:00AM |
| Updated: | Jun 01 2005 12:00AM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Symantec Brightmail Anti-Spam 6.0.1 Symantec Brightmail Anti-Spam 6.0 |
| Not Vulnerable: |
Symantec Brightmail Anti-Spam 6.0.2 |
Discussion
Symantec Brightmail AntiSpam Remote Information Disclosure Vulnerability
Symantec Brightmail AntiSpam is susceptible to a remote information disclosure vulnerability. This issue is due to a failure of the application to properly ensure that remote database access is properly disabled.
In cases where the affected package was upgraded, rather than freshly installed, remote database access was not properly disabled. Remote access to the database may be simplified for attackers, as the database utilizes a static password.
This vulnerability allows remote attackers to gain access to potentially sensitive database contents.
Symantec Brightmail AntiSpam is susceptible to a remote information disclosure vulnerability. This issue is due to a failure of the application to properly ensure that remote database access is properly disabled.
In cases where the affected package was upgraded, rather than freshly installed, remote database access was not properly disabled. Remote access to the database may be simplified for attackers, as the database utilizes a static password.
This vulnerability allows remote attackers to gain access to potentially sensitive database contents.
Exploit / POC
Symantec Brightmail AntiSpam Remote Information Disclosure Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Symantec Brightmail AntiSpam Remote Information Disclosure Vulnerability
Solution:
Symantec has released advisory SYM05-009, along with an upgrade of Symantec Brightmail AntiSpam to address this issue. Please see the referenced advisory for further information on obtaining fixes.
Solution:
Symantec has released advisory SYM05-009, along with an upgrade of Symantec Brightmail AntiSpam to address this issue. Please see the referenced advisory for further information on obtaining fixes.
References
Symantec Brightmail AntiSpam Remote Information Disclosure Vulnerability
References:
References:
- Brightmail Homepage (Symantec)
- SYM05-009 - Symantec Brightmail AntiSpam Static Database Password (Symantec)