CGI-Rescue Mail F/W System Unspecified Email Header Injection Vulnerability
BID:19676
CVE-2006-4344 |Info
CGI-Rescue Mail F/W System Unspecified Email Header Injection Vulnerability
| Bugtraq ID: | 19676 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 23 2006 12:00AM |
| Updated: | Aug 30 2006 11:43PM |
| Credit: | This vulnerability was reported by the vendor. |
| Vulnerable: |
CGI-Rescue Mail F/W 8.2 |
| Not Vulnerable: |
CGI-Rescue Mail F/W 8.3 |
Discussion
CGI-Rescue Mail F/W System Unspecified Email Header Injection Vulnerability
CGI-Rescue Mail F/W System is prone to an unspecified email-header-injection vulnerability.
Mail f/w fails to properly sanitize user-supplied input to an unspecified parameter or script when constructing email messages. This allows a malicious user to create an arbitrary email header, enabling the creation and transmission of spam messages from the affected computer.
Mail f/w version 8.2 is affected by this vulnerability; previous versions may be affected as well.
CGI-Rescue Mail F/W System is prone to an unspecified email-header-injection vulnerability.
Mail f/w fails to properly sanitize user-supplied input to an unspecified parameter or script when constructing email messages. This allows a malicious user to create an arbitrary email header, enabling the creation and transmission of spam messages from the affected computer.
Mail f/w version 8.2 is affected by this vulnerability; previous versions may be affected as well.
Exploit / POC
CGI-Rescue Mail F/W System Unspecified Email Header Injection Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
CGI-Rescue Mail F/W System Unspecified Email Header Injection Vulnerability
Solution:
The vendor has released an updated version that addresses this issue. Please see the vendor references for more information.
Solution:
The vendor has released an updated version that addresses this issue. Please see the vendor references for more information.
References
CGI-Rescue Mail F/W System Unspecified Email Header Injection Vulnerability
References:
References:
- Advisory ()
- JP Vendor Status Notes (JP Vendor Status Notes)
- Vendor Homepage (CGI-Rescue)