CVE-2006-3552: Medium severity Ipswitch Ipswitch Secure Server vulnerability
Premium Anti-Spam in Ipswitch IMail Secure Server 2006 and Collaboration Suite 2006 Premium, when using a certain .dat file in the StarEngine /data directory from 20060630 or earlier, does not properly receive and implement bullet signature updates, which allows context-dependent attackers to use the server for spam transmission.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3552?
CVE-2006-3552 is classified as a moderate severity vulnerability due to the potential for context-dependent attacks.
How do I fix CVE-2006-3552?
To resolve CVE-2006-3552, update the Premium Anti-Spam component to a version released after June 30, 2006.
What software is affected by CVE-2006-3552?
CVE-2006-3552 affects Ipswitch IMail Secure Server 2006 Premium and Collaboration Suite 2006 Premium.
What is the nature of the vulnerability described in CVE-2006-3552?
CVE-2006-3552 involves improper handling of bullet signature updates, which may allow attackers to exploit the system.
Is there a workaround for CVE-2006-3552 if I cannot update immediately?
A temporary workaround for CVE-2006-3552 is to disable the use of the vulnerable .dat files until an update can be applied.