[NT] GFI MailSecurity Web Module Buffer Overflow

From: SecuriTeam (support_at_securiteam.com)
Date: 10/17/05

  • Next message: SecuriTeam: "[REVS] Exploiting Windows Device Drivers"
    To: list@securiteam.com
    Date: 17 Oct 2005 10:01:14 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      GFI MailSecurity Web Module Buffer Overflow
    ------------------------------------------------------------------------

    SUMMARY

     <http://www.gfi.com/mailsecurity/> GFI MailSecurity is "a Content
    filtering, anti-virus and Email Intrusion prevention product from
    <http://www.gfi.com/> GFI".

    Buffer Overflow vulnerability discovered in web module of GFI MailSecurity
    product.

    DETAILS

    Vulnerable Systems:
     * GFI MailSecurity version 8.1

    Immune Systems:
     * GFI MailSecurity version 8.x patched with
    <ftp://ftp.gfi.com/patches/MSEC8_PATCH_20050919_01.zip>
    MSEC8_PATCH_20050919_01.zip

    An exploitable Buffer Overflow within the HTTP management interface has
    been identified. By sending large strings within several areas of the HTTP
    request (such as a large 'Host' or 'Accept' header) critical portions of
    memory are overwritten.

    Verification of this vulnerability can be achieved through the use of a
    HTTP fuzzer, such as @stake webproxy. Successful exploitation could allow
    an attacker to gain administrative control of the targeted host.

    Vendor Response:
    Vendor released patch and public notice.
     <http://kbase.gfi.com/showarticle.asp?id=KBID002451>
    http://kbase.gfi.com/showarticle.asp?id=KBID002451
     <ftp://ftp.gfi.com/patches/MSEC8_PATCH_20050919_01.zip>
    ftp://ftp.gfi.com/patches/MSEC8_PATCH_20050919_01.zip

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:garyo@sec-1.com> Gary
    O'leary-Steele.

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[REVS] Exploiting Windows Device Drivers"

    Relevant Pages

    • [UNIX] PHP cURL Safe_mode Bypass
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... PHP is "an HTML-embedded scripting language. ... supports HTTPS certificates, HTTP POST, HTTP PUT, FTP uploading (this can ...
      (Securiteam)
    • [NEWS] USRobotics USR808054 Wireless Access Point Denial Of Service And Possible Code Execution Vuln
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The USR808054 wireless router device can be administred via a web ... interface which is using the HTTP protocol. ...
      (Securiteam)
    • [UNIX] wget and curl NTLM Username Buffer Overflow
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... package for retrieving files using HTTP, HTTPS and FTP, the most ... curl supports HTTPS certificates, HTTP POST, ... The vulnerability specifically exists due to insufficient bounds checking ...
      (Securiteam)
    • [UNIX] Kaffeine Media Player Content-Type Overflow
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... A buffer overflow attack is possible in kaffeine by supplying a RealAudio ... http: content type = 'text/plain;' ... Previous frame inner to this frame ...
      (Securiteam)
    • [NEWS] GCALDaemon DoS
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Java program that offers two-way synchronization between Google Calendar ... over HTTP, by uploading their file via an HTTP PUT and getting/refreshing ...
      (Securiteam)