Gordano NTMail JUCE Email Filter Weakness
BID:6209
Info
Gordano NTMail JUCE Email Filter Weakness
| Bugtraq ID: | 6209 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 19 2002 12:00AM |
| Updated: | Nov 19 2002 12:00AM |
| Credit: | This vulnerability was reported by Geo <[email protected]>. |
| Vulnerable: |
Gordano NTMail 8.0 |
| Not Vulnerable: | |
Discussion
Gordano NTMail JUCE Email Filter Weakness
Gordano NTMail version 8 has an addon filter, JUCE, that allows for filtering of email based on defined properties. Reportedly, the JUCE filter does not adequately filter some email.
An attacker can exploit this weakness by sending an email with multiple recipients. The JUCE filter prevents the email from being delivered to the first recipient but fails to block delivery to the other recipients.
Gordano NTMail version 8 has an addon filter, JUCE, that allows for filtering of email based on defined properties. Reportedly, the JUCE filter does not adequately filter some email.
An attacker can exploit this weakness by sending an email with multiple recipients. The JUCE filter prevents the email from being delivered to the first recipient but fails to block delivery to the other recipients.
Exploit / POC
Gordano NTMail JUCE Email Filter Weakness
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Gordano NTMail JUCE Email Filter Weakness
Solution:
Fixes are available:
Gordano NTMail 8.0
Solution:
Fixes are available:
Gordano NTMail 8.0
-
Gordano smtp_h20021119.zip
ftp://ftp.gordano.com/gms/hotfixes/h20021119/intel/smtp_h20021119.zip
References
Gordano NTMail JUCE Email Filter Weakness
References:
References:
- Gordano Knowledge Base Article Q1709 (Gordano)
- NTMail Home Page (Gordano)