MailMarshal Tar Archive Remote Directory Traversal Vulnerability
BID:25523
Info
MailMarshal Tar Archive Remote Directory Traversal Vulnerability
| Bugtraq ID: | 25523 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 04 2007 12:00AM |
| Updated: | Sep 05 2007 08:31PM |
| Credit: | Sebastian Vandersee is credited with the discovery of this vulnerability. |
| Vulnerable: |
Marshal MailMarshal SMTP 6.2.1 Marshal MailMarshal SMTP 6.2 Marshal MailMarshal SMTP 6.1.9 Marshal MailMarshal SMTP 6.1.8 Marshal MailMarshal SMTP 6.0 Marshal MailMarshal SMTP 5.0 Marshal MailMarshal SMTP 2006 Marshal MailMarshal for Exchange 5.0 |
| Not Vulnerable: | |
Discussion
MailMarshal Tar Archive Remote Directory Traversal Vulnerability
MailMarshal is prone to a directory-traversal vulnerability because the application fails to validate user-supplied data.
Remote attackers an overwrite files in arbitrary locations on a vulnerable computer in the context of the user running the affected application.
MailMarshal is prone to a directory-traversal vulnerability because the application fails to validate user-supplied data.
Remote attackers an overwrite files in arbitrary locations on a vulnerable computer in the context of the user running the affected application.
Exploit / POC
MailMarshal Tar Archive Remote Directory Traversal Vulnerability
Attackers may exploit this issue by creating a malicious 'tar' archive.
Attackers may exploit this issue by creating a malicious 'tar' archive.
Solution / Fix
MailMarshal Tar Archive Remote Directory Traversal Vulnerability
Solution:
The vendor released updates to address this issue. Please see the references for more information.
Marshal MailMarshal SMTP 2006
Marshal MailMarshal SMTP 6.0
Marshal MailMarshal SMTP 5.0
Marshal MailMarshal for Exchange 5.0
Marshal MailMarshal SMTP 6.1.8
Marshal MailMarshal SMTP 6.1.9
Marshal MailMarshal SMTP 6.2
Marshal MailMarshal SMTP 6.2.1
Solution:
The vendor released updates to address this issue. Please see the references for more information.
Marshal MailMarshal SMTP 2006
-
Marshal Marshal_Q11780.zip
http://marshal.com/kb/attachments/Marshal_Q11780-GUIDb5cbc3d715f44ce39 e6bd888376761b1.zip
Marshal MailMarshal SMTP 6.0
-
Marshal Marshal_Q11780.zip
http://marshal.com/kb/attachments/Marshal_Q11780-GUIDb5cbc3d715f44ce39 e6bd888376761b1.zip
Marshal MailMarshal SMTP 5.0
-
Marshal Marshal_Q11780.zip
http://marshal.com/kb/attachments/Marshal_Q11780-GUIDb5cbc3d715f44ce39 e6bd888376761b1.zip
Marshal MailMarshal for Exchange 5.0
-
Marshal Marshal_Q11780MME.zip
http://marshal.com/kb/attachments/Marshal_Q11780_MMExchange-GUID08d2b9 9aa6ba4d1cab2df56190b30b1e.zip
Marshal MailMarshal SMTP 6.1.8
-
Marshal Marshal_Q11780.zip
http://marshal.com/kb/attachments/Marshal_Q11780-GUIDb5cbc3d715f44ce39 e6bd888376761b1.zip
Marshal MailMarshal SMTP 6.1.9
-
Marshal Marshal_Q11780.zip
http://marshal.com/kb/attachments/Marshal_Q11780-GUIDb5cbc3d715f44ce39 e6bd888376761b1.zip
Marshal MailMarshal SMTP 6.2
-
Marshal Marshal_Q11780.zip
http://marshal.com/kb/attachments/Marshal_Q11780-GUIDb5cbc3d715f44ce39 e6bd888376761b1.zip
Marshal MailMarshal SMTP 6.2.1
-
Marshal Marshal_Q11780.zip
http://marshal.com/kb/attachments/Marshal_Q11780-GUIDb5cbc3d715f44ce39 e6bd888376761b1.zip
References
MailMarshal Tar Archive Remote Directory Traversal Vulnerability
References:
References:
- MailMarshal Web Site (MailMarshal)
- Q11780 - FIX: MailMarshal Vulnerability to TAR Directory Traversal Attacks (MailMarshal)