Highly critical vulnerabilities confirmed

Oct 26, 2007 13:32 GMT  ·  By

Symantec Mail Security for SMTP is a technology designed by the famous company Symantec which is supposed to protect users' accounts from several types of web threats. Although the application has this clear goal, it seems like it might fail in its attempt to defend the users due to several vulnerabilities reported by security company Secunia and rated as highly critical. Secunia didn't mention how many security flaws were discovered but it sustained they can be easily exploited by an attacker to initiate DoS attacks in order to compromise an affected system.

"Multiple vulnerabilities have been discovered in Symantec Mail Security for SMTP, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system," Secunia wrote in the advisory. "The vulnerabilities are caused due to various errors within certain third-party file viewers and can be exploited to cause buffer overflows when a specially crafted file is checked."

It seems like the only affected version of the application is the 5.0.1 release without Patch 181 and 182. However, other editions might be also affected by the flaws. "Successful exploitation allows execution of arbitrary code, but requires that e.g. a policy is setup for scanning the contents of messages," Secunia added.

In order to remain protected and avoid successful exploitation of the vulnerabilities, you have to install the two patches available here (patch 181) and here (patch 182). Both of them are hosted by Symantec.

Symantec is a pretty famous company with very powerful technologies which are installed on millions of computers from all over the world. Just have a look at Norton Antivirus, a security software which aims to discover and eliminate the reported viruses from users' computers. Norton Antivirus is one of the most successful products when it comes to the number of clients, being one of the top players on the security market.