what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

mailmarshall-password.txt

mailmarshall-password.txt
Posted Jul 18, 2007
Authored by Gary O'Leary-Steele | Site sec-1.com

The MailMarshal Spam Quarantine version 6.2.0.x HTTP interface password reset facility is vulnerable to a SQL buffer truncation attack. The vulnerability could be exploited to reset and retrieve any user account. The attacker would require prior knowledge of the users email address.

tags | advisory, web
advisories | CVE-2007-3796
SHA-256 | 413e168c92dfcc339ecd500754b6e240ebd1b59e709f687e96ac02bb9c73e549

mailmarshall-password.txt

Change Mirror Download
                           SEC-1 LTD.

www.sec-1.com

Security Advisory

Advisory Name: MailMarshal Spam Quarantine Password Retrieval
Vulnerability

Release Date: 17-06-2007
Application: MailMarshal SMTP 6.2.0.x

Platform: Microsoft Windows
Severity: Password Retrieval
Author: Gary O'leary-Steele
Reported: See time line section below
Vendor status: Fix Available
CVE Candidate: CVE-2007-3796
Reference: http://www.sec-1.com/


Overview from www.mailmarshal.com:

MailMarshal SMTP is a total email content security solution for business
networks. It combines anti-spam, anti-virus, anti-phishing, anti-porn
and
content security into a highly scalable and easily manageable solution.
MailMarshal enables you to meet your corporate obligation to provide a
safe and secure environment for your employees. It also enables you to
meet
your obligation to effectively monitor and manage your organization's
compliance with relevant corporate governance and legislative regulatory
frameworks.


Vulnerability Summary:

The Spam Quarantine HTTP interface password reset facility is vulnerable

to a SQL buffer truncation attack. The vulnerability could be exploited
to reset and retrieve any user account. The attacker would require prior

knowledge of the users email address.


Vulnerability Details:

A technical analysis of the vulnerability is included within our
"Buffer Truncation in Microsoft SQL Server Based Applications 1.1" paper


http://www.sec-1labs.co.uk/advisories/BTA_Full.pdf


Time Line:

24/05/2007 Reported
12/07/2007 Fix Available


Vendor Status:

This issue has been resolved in version 6.2.1. See the change history
for further
details.

http://www.marshal.com/software/mailmarshal_smtp/MailMarshalSMTP-Release
Notes-6.2.1.3252.htm#Change%20History


Common Vulnerabilities and Exposures (CVE) Information:

The Common Vulnerabilities and Exposures (CVE) project has assigned
the following names to these issues. These are candidates for
inclusion in the CVE list (http://cve.mitre.org), which standardizes
names for security problems.


CVE-2007-3796

Copyright 2007 Sec-1 LTD. All rights reserved.

Sec-1 specialises in the provision of network security solutions.
For more information on products and services we offer visit
www.sec-1.com
or call
0113 257 8955.

Login or Register to add favorites

File Archive:

May 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    44 Files
  • 2
    May 2nd
    5 Files
  • 3
    May 3rd
    11 Files
  • 4
    May 4th
    0 Files
  • 5
    May 5th
    0 Files
  • 6
    May 6th
    28 Files
  • 7
    May 7th
    3 Files
  • 8
    May 8th
    4 Files
  • 9
    May 9th
    54 Files
  • 10
    May 10th
    12 Files
  • 11
    May 11th
    0 Files
  • 12
    May 12th
    0 Files
  • 13
    May 13th
    17 Files
  • 14
    May 14th
    11 Files
  • 15
    May 15th
    17 Files
  • 16
    May 16th
    13 Files
  • 17
    May 17th
    22 Files
  • 18
    May 18th
    0 Files
  • 19
    May 19th
    0 Files
  • 20
    May 20th
    17 Files
  • 21
    May 21st
    18 Files
  • 22
    May 22nd
    7 Files
  • 23
    May 23rd
    111 Files
  • 24
    May 24th
    0 Files
  • 25
    May 25th
    0 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close