Critical Symantec flaws threaten Exchange e-mail

By Tom Espiner, ZDNet UK
31 October 2007 08:03 AM
Tags: critical, exchange, flaw, mail, symantec, email, threat, secunia

There are currently a number of "highly critical" unpatched security flaws in Symantec Mail Security for Microsoft Exchange versions 4.x, 5.x, and 6.x, according to Secunia.

In an advisory published on Monday, Secunia warned that companies could suffer remote systems access and denial of service due to unpatched parsing vulnerabilities in Symantec Mail Security for Microsoft Exchange, caused by third-party file viewers.

"Multiple vulnerabilities have been discovered in Symantec Mail Security for Exchange, which can be exploited by malicious people to cause a DoS (denial of service) and compromise a vulnerable system," the advisory, SA27429, stated. "The vulnerabilities are caused due to various errors within certain third-party file viewers and can be exploited to cause buffer overflows when a specially crafted file is checked."

The vulnerabilities have been confirmed in Symantec Mail Security for Exchange version 5.0.7.373, but Secunia warned that other versions may also be affected.

Secunia is currently not aware of any available patches, and advises businesses to disable the scanning of message content, if enabled.

Symantec had not responded to a request for comment at the time of writing.

Advertisement

Talkback 0 comments

Latest Videos

Blogs

  • Darren Greenwood Telecom NZ savings damage prospects
    If Telecom NZ wants to have any of the NZ$1.5 billion the government intends to spend on its new broadband network, it had better think long and hard before offshoring 1500 jobs.
  • Array iiNet: The whys and what nows
    Last week the Federal Court ruled that internet service providers are not responsible for copyright violation by their customers. This is an important decision not just for iiNet, which spent around $4 million defending the case, but for all ISPs in Australia and, indeed, globally.
  • Array Govt, hurry up with releasing data
    A programmer scraped data from the My School website to make some really cool heat maps showing regions of smart schools — no thanks to the government, which didn't supply the data in any useful kind of format.
  • More blogs »

Tags

Back to top

Featured