Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Marshal MailMarshal UNARJ Extraction Remote Directory Traversal Vulnerability

Marshal MailMarshal is affected by a remote directory-traversal vulnerability because the application fails to properly sanitize or validate filenames prior to decompression.

Exploiting this issue may allow an attacker to arbitrarily overwrite files with a user's privileges when a malicious compressed file is decompressed with the affected application.

MailMarshal SMTP 5.x, MailMarshal SMTP 6.x, MailMarshal SMTP 2006, and MailMarshal for Exchange 5.x are vulnerable; other versions may also be affected.







 

Privacy Statement
Copyright 2008, SecurityFocus