Home > Security News > Researchers flag Symantec Mail Security flaws
Security News:
EMAIL THIS

Researchers flag Symantec Mail Security flaws

By SearchSecurity.com Staff
29 Oct 2007 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Attackers could exploit "highly critical" vulnerabilities in Symantec Mail Security for SMTP, Exchange and Domino to cause a denial of service and compromise targeted machines, researchers warned over the weekend.

Danish vulnerability clearinghouse Secunia issued three advisories on the flaws, all of which it labeled "highly critical," its second-highest severity designation typically reserved for remotely exploitable flaws that can lead to system compromise. Successful exploitation does not normally require any interaction but there are no known exploits available at the time of disclosure, Secunia notes on its Web site.

Secunia advisory SA27429 describes multiple vulnerabilities in Symantec Mail Security for Exchange due to various errors within certain third-party file viewers. Attackers could exploit the flaws to cause buffer overflows when a specially crafted file is checked. Secunia is not aware of patches for these issues, and recommended users disable scanning of message content as a precaution.

Secunia advisory SA27388 describes similar vulnerabilities in Symantec Mail Security for Domino. Secunia noted the flaws are not yet patched and offered the same advice as in SA27429.

Secunia advisory SA27367 describes similar vulnerabilities in Symantec Mail for SMTP, but notes that Symantec quietly fixed the SMTP variant of the flaw with Patch 181 and 182 for version 5.0.1.



Tags: Email Security Guidelines, Encryption and AppliancesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Email Security Guidelines, Encryption and Appliances
What does 'invoked by uid 78' mean?
How to configure firewall ports for webmail system implementation
Fierce competition prompted new Cisco email security options
Cisco brings email security appliances closer to SaaS
Cisco offers more email security choices, but lacks vision
Information security book excerpts and reviews
Are message stubs a secure part of email retention policies?
Strategies for email archiving and meeting compliance regulations
Product Review: Astaro Mail Gateway 4000
What are the security risks of opening port 110 and port 25?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
asymmetric cryptography  (SearchSecurity.com)
challenge-response system  (SearchSecurity.com)
cryptographic checksum  (SearchSecurity.com)
data encryption/decryption IC  (SearchSecurity.com)
elliptical curve cryptography  (SearchSecurity.com)
Escrowed Encryption Standard  (SearchSecurity.com)
MPPE  (SearchSecurity.com)
Quiz: Cryptography  (SearchSecurity.com)
session key  (SearchSecurity.com)
Twofish  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts