Symantec Messaging Gateway CVE-2012-3581 Information Disclosure Vulnerability
BID:55142
Info
Symantec Messaging Gateway CVE-2012-3581 Information Disclosure Vulnerability
| Bugtraq ID: | 55142 |
| Class: | Design Error |
| CVE: |
CVE-2012-3581 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 27 2012 12:00AM |
| Updated: | Aug 27 2012 12:00AM |
| Credit: | Ben Williams with NGS Secure |
| Vulnerable: |
Symantec Messaging Gateway 9.5.1 Symantec Messaging Gateway 9.5 |
| Not Vulnerable: | |
Discussion
Symantec Messaging Gateway CVE-2012-3581 Information Disclosure Vulnerability
Symantec Messaging Gateway is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may aid in launching further attacks.
Symantec Messaging Gateway 9.5.x versions are vulnerable.
Symantec Messaging Gateway is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may aid in launching further attacks.
Symantec Messaging Gateway 9.5.x versions are vulnerable.
Exploit / POC
Symantec Messaging Gateway CVE-2012-3581 Information Disclosure Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Symantec Messaging Gateway CVE-2012-3581 Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Symantec Messaging Gateway CVE-2012-3581 Information Disclosure Vulnerability
References:
References:
- Messaging Gateway Homepage (Symantec)
- SYM12-013: Symantec Messaging Gateway Security Issues (Symantec)