OSVDB ID: 24366

Title: McAfee WebShield SMTP Bounce Message Format String

Info

Disclosure

Apr 03, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

WebShield SMTP contains a flaw that may allow a malicious user to execute arbitrary code. The issue is triggered due to a format string error within the construction of bounce messages for non-existent domains. It is possible that the flaw may allow remote code execution resulting in a loss of integrity.

Classification

Location: Remote / Network Access, Local / Remote, Context Dependent
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Rumored
Disclosure: OSVDB Verified
OSVDB: Security Software

Solution

Upgrade to version 4.5 MR2 or higher, as it has been reported to fix this vulnerability. In addition, the vendor has released a patch for some older versions.

Products

McAfee, Inc.

WebShield SMTP

4.5 MR1a

References

Credit

  • Ollie Whitehouse - ollie_whitehousesymantec.com - Symantec Corp.


Direct URL: http://osvdb.org/24366