|
|
Info |
Last Modified |
| about 1 year ago |
|
|
|
|
|
Description |
Symantec Brightmail AntiSpam contains a flaw that may allow a remote denial of service. The issue is triggered when impersonating the "Control Center" and sending invalid posts to the Brightmail AntiSpam service. This will result in loss of availability for the SBAS service.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Denial of Service,
Input Manipulation
Impact:
Loss of Availability
Exploit:
Exploit Unavailable
Disclosure:
OSVDB Verified
|
|
Technical |
This vulnerability is only present when the Control Center is configured to allow connections from any computer.
|
|
Solution |
Upgrade to version 6.0.4 or upgrade to Symantec Mail Security for SMTP 5.0 , as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
Brightmail AntiSpam
 |
4.x |
5.x |
6.x |
6.0.4 |
|
|
|
|
|
|
Credit |
- George A. Theall - theall
tenablesecurity.com - TenableSecurity
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|