|
Novell Netmail Script Insertion Vulnerability
|
|
|
|
|
Secunia Advisory:
|
SA15962
|
|
|
Release Date:
|
2005-07-08
|
|
Last Update:
|
2005-10-12
|
|
|
Critical:
|

Moderately critical
|
|
Impact:
|
Cross Site Scripting
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | Novell NetMail 3.x
|
| | CVE reference: | CVE-2005-2176 (Secunia mirror)
|
|
|
Want to know the next time vulnerabilities are fixed in this product? - Companies can be alerted via email and SMS! |
|
|
Description: shalom has discovered a vulnerability in Netmail, which can be exploited by malicious people to conduct script insertion attacks.
The vulnerability is caused due to unsafe rendering of HTML file attachments when an email is opened for viewing. This can be exploited to inject arbitrary HTML and script code, which will be executed in a user's browser session in context of an affected site when the email containing the malicious HTML attachment is viewed.
The vulnerability has been confirmed in version 3.52. Prior versions may also be affected.
Solution: Update to version 3.52D.
NetWare:
http://support.novell.com/servlet/filedownload/pub/netmail352d_nw.zip
Windows:
http://support.novell.com/servlet/filedownload/pub/netmail352d_win.zip
Linux:
http://support.novell.com/servlet/filedownload/sec/pub/netmail352d_lin.tgz
Provided and/or discovered by: shalom
Changelog: 2005-07-12: Added CVE reference.
2005-10-11: Updated "Solution" section.
|
|
|
|
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
|
13 Related Secunia Security Advisories, displaying 10
|
|
|
1. Novell NetMail AntiVirus Agent Integer Overflow Vulnerability
|
|
2. Novell NetMail NMDMC.EXE Buffer Overflow Vulnerability
|
|
3. Novell Netmail WebAdmin Long Username Buffer Overflow
|
|
4. Novell NetMail NMAP/IMAP Multiple Vulnerabilities
|
|
5. Novell Products Two Buffer Overflow Vulnerabilities
|
|
6. Novell NetMail IMAP Buffer Overflow Vulnerability
|
|
7. Novell NetMail NMAP Agent "USER" Buffer Overflow Vulnerability
|
|
8. Novell NetMail File Ownership Security Issue
|
|
9. Novell NetMail Multiple Vulnerabilities
|
|
10. NetMail IMAPD Unspecified Buffer Overflow Vulnerability
|
Show all related advisories
|
|
|
Send Feedback to Secunia
|
|
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.
|
|
|
|