MailScanner Attachment Filename Validation Vulnerability

A vulnerability has been reported in how MailScanner handles filenames for attachments.

It may be possible to bypass MailScanner security with attachment filenames that contain excessive trailing/leading whitespace, are blank, or use character encodings that are unknown to MailScanner.

The exact consequences of this vulnerability are not known.


 

Privacy Statement
Copyright 2010, SecurityFocus