TITLE:
Symantec Firewall Devices SMTP Binding Configuration Bypass

SECUNIA ADVISORY ID:
SA14428

VERIFY ADVISORY:
http://secunia.com/advisories/14428/

CRITICAL:
Less critical

IMPACT:
Exposure of sensitive information

WHERE:
>From remote

OPERATING SYSTEM:
Symantec Firewall/VPN Appliance 100/200/200R
http://secunia.com/product/552/
Symantec Gateway Security 2.x
http://secunia.com/product/3104/
Symantec Nexland Firewall Appliances 1.x
http://secunia.com/product/4466/

DESCRIPTION:
A security issue in various Symantec firewall devices,
which may disclose sensitive information to
malicious people.

The problem is caused due to an error in the SMTP
binding functionality of certain devices with ISP
load-balancing capabilities. This results in outbound
email traffic being load-balanced regardless of the
configured WAN binding selection, which may cause
sensitive SMTP traffic only destined for a trusted
network to be passed over an untrusted connection.

The security issue has been reported in the following
versions:
* Symantec Firewall/VPN Appliance 200/200R
(firmware builds prior to build 1.68 and later than 1.5Z)
* Symantec Gateway Security 360/360R
(firmware builds prior to build 858)
* Symantec Gateway Security 460/460R
(firmware builds prior to build 858)
* Nexland Pro800turbo
(firmware builds prior to build 1.6X and later than 1.5Z)

SOLUTION:
The vendor has issued updated firmware releases.
http://www.symantec.com/techsupp

Symantec Firewall/VPN Appliance models 200 and 200R:
Update to build 1.68.

Symantec Gateway Security Appliance 300 and 400 series:
Update to build 858.

Nexland Pro800turbo:
Update to build 1.6X.

ORIGINAL ADVISORY:
http://securityresponse.symantec.com/avcenter/security/Content/2005.02.28.html
============= PCWorks Mailing List =================
Don't see your post? Check our posting guidelines &
make sure you've followed proper posting procedures,
http://pcworkers.com/rules.htm
Contact list owner <[EMAIL PROTECTED]>
Unsubscribing and other changes: http://pcworkers.com
=====================================================

Reply via email to