CVE-2000-0318: High severity atrium software mercur mailserver vulnerability
Atrium Mercur Mail Server 3.2 allows local attackers to read other user's email and create arbitrary files via a dot dot (..) attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Mercury Mail Serverfrom your environment.If Mercury Mail Server is not required, uninstall it from affected hosts to eliminate the vulnerable software.
- Compensating control
Restrict and harden access to hosts running Mercury Mail Server: remove or disable untrusted local user accounts, limit interactive logins to trusted administrators, isolate the mail server on a dedicated host or VM, and enforce OS-level access controls (file permissions/mandatory access control) to prevent local users from reading other users' mail or creating arbitrary files.
- Operational
Audit affected hosts for indicators of compromise (unauthorized file creation, access to other users' mail) and, if compromise is suspected, rotate credentials and keys that may have been exposed prior to applying mitigation or removal.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0318?
The severity of CVE-2000-0318 is considered moderate as it allows local attackers to access other users' emails and create arbitrary files.
How do I fix CVE-2000-0318?
To fix CVE-2000-0318, upgrade to a later version of the Atrium Mercur Mail Server that addresses this vulnerability.
Who is affected by CVE-2000-0318?
Users of Atrium Mercur Mail Server version 3.2 are affected by CVE-2000-0318.
What kind of attack does CVE-2000-0318 allow?
CVE-2000-0318 allows for a dot dot (..) attack that can lead to unauthorized access to other users' emails.
Is there a workaround for CVE-2000-0318?
As of now, the best mitigation for CVE-2000-0318 is to apply the available software update or patch.