First published: Thu Jul 13 2006(Updated: )
Premium Anti-Spam in Ipswitch IMail Secure Server 2006 and Collaboration Suite 2006 Premium, when using a certain .dat file in the StarEngine /data directory from 20060630 or earlier, does not properly receive and implement bullet signature updates, which allows context-dependent attackers to use the server for spam transmission.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ipswitch Secure Server | =2006_premium | |
Ipswitch Ipswitch Collaboration Suite | =2006_premium |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3552 is classified as a moderate severity vulnerability due to the potential for context-dependent attacks.
To resolve CVE-2006-3552, update the Premium Anti-Spam component to a version released after June 30, 2006.
CVE-2006-3552 affects Ipswitch IMail Secure Server 2006 Premium and Collaboration Suite 2006 Premium.
CVE-2006-3552 involves improper handling of bullet signature updates, which may allow attackers to exploit the system.
A temporary workaround for CVE-2006-3552 is to disable the use of the vulnerable .dat files until an update can be applied.