There are time when vulnerabilities pop up that bother me. I know for most it means patching et cetera. But, in this instance it’s a product that I particularly like. Brightmail, who was purchased by Symantec last year(ish) has been amalgamated into the Symantec Mail Security offering as well as a standalone antispam offering. It works quite well. I’ve had this one in the lab and tested it. A very nice product. But, if you use this be sure to read on and patch ‘er up. Secunia gives this one a Moderately critical rating.

Description:
Some vulnerabilities have been reported in Symantec Brightmail AntiSpam, which can be exploited by malicious people to cause a DoS (Denial of Service) and overwrite or read sensitive information.

1) When installing e-mail scanners, it is possible to select an option that allows the Control Center to connect from any computer. If this option is selected, it is possible to impersonate the Control Center and cause the Brightmail AntiSpam service to stop responding by sending invalid posts.

2) Input passed in “DATABLOB-GET” and “DATABLOB-SAVE” requests is not properly sanitised. This can be exploited to overwrite or read some files on the system in combination with vulnerability #1.

Solution:
Update to version 6.0.4 or upgrade to Symantec Mail Security for SMTP 5.0.

Article Link

[tags]Brightmail Vulnerability, Symantec, SMS, Antispam[/tags]

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.