PT-2002-3120 · Gordano · Gordano Messaging Server (Gms) Mail

Publicado

2002-12-31

·

Atualizado

2008-09-05

·

CVE-2002-2408

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Gordano Messaging Server (GMS) Mail 8
Description The issue allows remote attackers to bypass JUCE filters by sending an email message to more than one user on the GMS server, as the server only filters email messages for the first recipient.
Recommendations For Gordano Messaging Server (GMS) Mail 8, consider implementing a workaround to filter email messages for all recipients, not just the first one, until a proper fix is available. As a temporary mitigation measure, restrict the ability to send emails to multiple users simultaneously to minimize the risk of filter bypass.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-2408

Produtos afetados

Gordano Messaging Server (Gms) Mail