Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Advisories

December 13th, 2007, 19:06 GMT · By Bogdan Popa

Mail Security Not so Secure

SHARE:

Adjust text size:


Symantec Mail Security
Enlarge picture
A highly critical vulnerability has been discovered in Symantec Mail Security, which may allow an attacker who manages to exploit it to compromise the affected system, Secunia wrote in a security notification rolled out today. The flaw exists in Symantec Mail Security
for SMTP version 5.0.1 with Patch 187, but other versions might be affected as well. Symantec Mail Security is a technology powered by the Cupertino company, being supposed to protect the inboxes from all kinds of threats, including spam and other unsolicited messages. Today's flaw was rated as highly critical by Secunia, so we're still waiting for an official response from Symantec.

"The vulnerabilities are caused due to various errors within the third-party Lotus 1-2-3 file viewer and can be exploited to cause buffer overflows when a specially crafted file is checked. Successful exploitation allows execution of arbitrary code, but requires that e.g. a policy is setup for scanning the contents of messages", Secunia wrote in the advisory.

There's no patch available yet, but the only solution to avoid a successful exploitation of the vulnerability is to "disable scanning of message content if enabled", as Secunia added.

This isn't the first time when Symantec's products are affected by more or less critical vulnerabilities, although we all know the company's tools are pretty efficient when it comes to blocking threats. And these vulnerabilities are only good things, because it proves us that he company is still working on it, so better performance in expected anytime soon.

However, Symantec has always managed to patch the flaws in no time, so I believe there's no risk if you avoid dangerous content and apply Secunia's solution. In addition, you can always keep an eye on the security news in order to know if there's any patch available, or worse, if other vulnerabilities have been discovered.

TELL US WHAT YOU THINK:

1,027 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


A Not-So-Safe-Email with Symantec Mail Security

Get Symantec Security Software without Paying!

Fear Not, Users! Symantec Will Save the Day!

New Symantec Security Solution Hits the Web

Is that Software Valued at $25,000 Belonging to Symantec?

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM