Multiple Vendor SMTP Attachment Protection Bypass Vulnerability
BID:3097
Info
Multiple Vendor SMTP Attachment Protection Bypass Vulnerability
| Bugtraq ID: | 3097 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 25 2001 12:00AM |
| Updated: | Jul 25 2001 12:00AM |
| Credit: | Reported to the securiteam mailing list by "Huskey, Clark" <[email protected]> on July 25, 2001, with credit to Aidan <[email protected]>. |
| Vulnerable: |
Trend Micro ScanMail 1.0 Softek MailMarshal 4.2 Softek MailMarshal 4.1 Softek MailMarshal 4.0 |
| Not Vulnerable: | |
Discussion
Multiple Vendor SMTP Attachment Protection Bypass Vulnerability
At least two SMTP gateway products have been identified which contain flaws in the handling of restricted filetypes as attachments.
An attacker can insert extraneous characters in the filename extension of a hostile attachment.
The affected gateway will fail to detect the modified extension. Since Microsoft Outlook removes illegal characters in extensions, the executable attachment is delivered to the recipient user with its normal, working extension intact.
At least two SMTP gateway products have been identified which contain flaws in the handling of restricted filetypes as attachments.
An attacker can insert extraneous characters in the filename extension of a hostile attachment.
The affected gateway will fail to detect the modified extension. Since Microsoft Outlook removes illegal characters in extensions, the executable attachment is delivered to the recipient user with its normal, working extension intact.
Solution / Fix
Multiple Vendor SMTP Attachment Protection Bypass Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.