Symantec Brightmail AntiSpam Control Center Multiple Vulnerabilities
BID:19182
CVE-2006-4013 | CVE-2006-4014 |Info
Symantec Brightmail AntiSpam Control Center Multiple Vulnerabilities
| Bugtraq ID: | 19182 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-4013 CVE-2006-4014 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 27 2006 12:00AM |
| Updated: | Jul 06 2016 12:17PM |
| Credit: | George A. Theall of Tenable Network Security Inc. is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Symantec Brightmail Anti-Spam 6.0.3 Symantec Brightmail Anti-Spam 6.0.2 Symantec Brightmail Anti-Spam 6.0.1 Symantec Brightmail Anti-Spam 6.0 Symantec Brightmail Anti-Spam 5.5 Symantec Brightmail Anti-Spam 4.0 |
| Not Vulnerable: |
Symantec Mail Security for SMTP 5.0 Symantec Brightmail Anti-Spam 6.0.4 |
Discussion
Symantec Brightmail AntiSpam Control Center Multiple Vulnerabilities
Symantec Brightmail AntiSpam is prone to multiple vulnerabilities, including an unauthorized-access vulnerability, a directory-traversal vulnerability, and a denial-of-service vulnerability.
An attacker can exploit these issues to expose potentially sensitive information, overwrite existing data, or cause the application to hang, effectively denying service to legitimate users.
Symantec Brightmail AntiSpam is prone to multiple vulnerabilities, including an unauthorized-access vulnerability, a directory-traversal vulnerability, and a denial-of-service vulnerability.
An attacker can exploit these issues to expose potentially sensitive information, overwrite existing data, or cause the application to hang, effectively denying service to legitimate users.
Exploit / POC
Symantec Brightmail AntiSpam Control Center Multiple Vulnerabilities
To exploit these issues, attackers can use regularly available networking tools.
To exploit these issues, attackers can use regularly available networking tools.
Solution / Fix
Symantec Brightmail AntiSpam Control Center Multiple Vulnerabilities
Solution:
Symantec advises all current SBAS customers to upgrade to SMS for SMTP 5.0, which does not have this vulnerability. All SBAS customers with current maintenance agreements are entitled to upgrade to SMS for SMTP 5.0 at no additional cost.
For customers unable to upgrade to SMS for SMTP 5.0, Symantec has created and released SBAS 6.0.4, a product update that addresses this vulnerability. SBAS 6.0.4 properly sanitizes all directory-traversal input.
Solution:
Symantec advises all current SBAS customers to upgrade to SMS for SMTP 5.0, which does not have this vulnerability. All SBAS customers with current maintenance agreements are entitled to upgrade to SMS for SMTP 5.0 at no additional cost.
For customers unable to upgrade to SMS for SMTP 5.0, Symantec has created and released SBAS 6.0.4, a product update that addresses this vulnerability. SBAS 6.0.4 properly sanitizes all directory-traversal input.
References
Symantec Brightmail AntiSpam Control Center Multiple Vulnerabilities
References:
References:
- F-Secure Homepage (F-Secure)
- Symantec Brightmail Anti-Spam Homepage (Symantec Corp.)
- Symantec Brightmail AntiSpam Multiple Vulnerabilities (Symantec)