|
|
|
View Notes By
|
|
|
|
Other Documents
|
|
|
|
|
Vulnerability Note VU#697598
Symantec Brightmail Anti-Spam Spamhunter UTF encoding error
OverviewSymantec Brightmail Anti-Spam Spamhunter crashes when trying to convert certain valid character sets to UTF, resulting in a denial-of-service condition.
I. DescriptionBrightmail Anti-Spam Spamhunter is a spam filter designed for corporate environments. The Brightmail Anti-Spam Spamhunter module cannot parse the following character sets:
- ISO-8859-10 (Latin 6)
- ISO-8859-13 (Latin 7)
- ISO-8859-15 (Nordic)
- CP866 (Russian)
According to the notes included with Spamhunter Patch 132:
The character converters used by the Spamhunter and Language ID modules do not recognize certain valid character encoding sets, specifically ISO-8859-10, ISO-8859-13, ISO-8859-15 (nordic), and CP866 (russian). Previously, these modules assumed that a valid encoding meant the converter would recognize the character set. In the case of ISO-8859-10, when the converter did not recognize the character set, a crash would result.
II. ImpactIf a remote attacker supplies the Brightmail Anti-Spam Spamhunter with a specially crafted email that is encoded with one of the character sets Spamhunter cannot parse (see list above), that attacker may be able to crash the service resulting in a denial-of-service condition.
III. SolutionApply Patch
Symantec has released a Patch 132 to correct this issue.
Systems Affected
References
ftp://ftp.symantec.com/public/english_us_canada/products/sba/sba_60x/updates/p132_notes.htm
http://secunia.com/advisories/13489/
http://www.osvdb.org/displayvuln.php?osvdb_id=12459
http://xforce.iss.net/xforce/xfdb/18530
Credit
This vulnerability was publicly reported by Symantec.
This document was written by Jeff Gennari.
Other Information
| Date Public: | 2004-12-17 |
| Date First Published: | 2005-01-05 |
| Date Last Updated: | 2005-01-05 |
| CERT Advisory: | |
| CVE-ID(s): | |
| NVD-ID(s): | |
| US-CERT Technical Alerts: | |
| Metric: | 3.00 |
| Document Revision: | 61 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
|