lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <DE5B0CD0A5DEE04F9147D08BF6DD21DF08B4CD@sec1svr03.SEC1SVR2003.sec-1.com>
Date: Wed, 12 Oct 2005 11:59:37 +0100
From: "Gary Oleary-Steele" <garyo@...-1.com>
To: <bugtraq@...urityfocus.com>, <full-disclosure@...ts.grok.org.uk>
Cc: Vuln-Dev@...urityfocus.com, pen-test@...urityfocus.com,
	security@...ts.seifried.org
Subject: [SEC-1 Advisory] GFI MailSecurity 8.1 Web Module
	Buffer Overflow


                                SEC-1 LTD.
                              www.sec-1.com

                             Security Advisory

Advisory Name:	GFI MailSecurity 8.1 Web Module Buffer Overflow
 Release Date:	12/October/2005
  Application: 	GFI MailSecurity For SMTP version 8.1

     Platform: 	Verified on Windows 2000 Server
     Severity: 	Remote Code Execution 
       Author: 	Gary O'leary-Steele 
Vendor Status: 	Patch Released
CVE Candidate: 	Pending
    Reference:  	http://www.sec-1.com


Overview: 

Taken from gfi.com:

GFI MailSecurity for SMTP is a Content filtering, anti-virus and 
Email Intrusion prevention product from GFI.

GFI MailSecurity is available as an SMTP gateway version and for 
VS API. The gateway version should be deployed at the perimeter 
of the network as a mail relay server and scans inbound and 
outbound mail. The VS API version integrates seamlessly with 
Exchange Server 2000/2003 and scans the Exchange information stores.
Both versions can be deployed simultaneously to achieve optimum 
protection.


Vulnerability Details: 

Sec-1 has identified an exploitable Buffer Overflow within the HTTP
management interface. By sending large strings within several areas
of the HTTP request (such as a large 'Host' or 'Accept' header)
critical portions of memory are overwritten. Verification of this
vulnerability can be achieved through the use of a HTTP fuzzer, such 
as @stake webproxy. Successful exploitation could allow an attacker
to gain administrative control of the targeted host.


Vendor Response:

The vendor has released information and a patch

KB:	http://kbase.gfi.com/showarticle.asp?id=KBID002451
Patch: ftp://ftp.gfi.com/patches/MSEC8_PATCH_20050919_01.zip

Common Vulnerabilities and Exposures (CVE) Information:

The Common Vulnerabilities and Exposures (CVE) project has assigned 
the following names to these issues.  These are candidates for 
inclusion in the CVE list (http://cve.mitre.org), which standardizes 
names for security problems.


Pending

Copyright 2005 Sec-1 LTD. All rights reserved.
**************************************************************
NEW: Sec-1 Hacking Training - Learn to breach network security 
to further your knowledge and protect your network 
http://www.sec-1.com/applied_hacking_course.html
**************************************************************
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ