更新日期:2007-09-05
受影响系统:
Marshal MailMarshal SMTP 6.x描述:
Marshal MailMarshal SMTP 5.5
Marshal MailMarshal SMTP 2006
Marshal MailMarshal for Exchange 5.x
BUGTRAQ ID: 25523
MailMarshal SMTP是适用于业务网络的邮件安全解决方案。
如果远程攻击者发送了文件名中包含有目录遍历序列标识符的tar文档的话,则MailMarshal SMTP在解压该文档时可能会向系统中的任意目录(如开始菜单)写入文件。
<*来源:Sebastian Vandersee (discuss@rt-solutions.de)
链接:http://secunia.com/advisories/26661/
http://marshal.com/kb/article.aspx?id=11780
http://marc.info/?l=bugtraq&m=118891868224455&w=2
*>
建议:
厂商补丁:
Marshal
-------
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:
http://marshal.com/kb/attachments/Marshal_Q11780_MMExchange-GUID08d2b99aa6ba4d1cab2df56190b30b1e.zip
http://marshal.com/kb/attachments/Marshal_Q11780-GUIDb5cbc3d715f44ce39e6bd888376761b1.zip
