CVE-1999-1017: High severity Seattle Lab Software Emurl vulnerability
Seattle Labs Emurl 2.0, and possibly earlier versions, stores e-mail attachments in a specific directory with scripting enabled, which allows a malicious ASP file attachment to execute when the recipient opens the message.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable server-side scripting/execution for the directory where Emurl stores e-mail attachments so that uploaded ASP (and other executable script) files cannot be executed when a message is opened.
Seattle Lab Software Emurl attachment storage directory script execution = disabled - Compensating control
Block or filter e-mail attachments with server-side script extensions (for example .asp) at the mail gateway/antivirus/secure mail appliance to prevent delivery of potentially executable attachments to recipients.
- Operational
Scan the attachment storage location and mailboxes for existing .asp or other executable script attachments and remove any malicious files; notify affected users and quarantine suspicious items for analysis.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1017?
CVE-1999-1017 is considered a high severity vulnerability due to the risk of executing malicious scripts through email attachments.
How do I fix CVE-1999-1017?
To fix CVE-1999-1017, you should upgrade to a version of Seattle Labs Emurl that is later than 2.0 or disable scripting in the directory that stores email attachments.
What types of software are affected by CVE-1999-1017?
CVE-1999-1017 affects Seattle Labs Emurl version 2.0 and possibly earlier versions.
What kind of attack is enabled by CVE-1999-1017?
CVE-1999-1017 potentially allows attackers to execute malicious ASP files when users open email messages containing these attachments.
Who is impacted by CVE-1999-1017?
Users of Seattle Labs Emurl version 2.0 and below are impacted by CVE-1999-1017, particularly those who receive email attachments.