First published: Wed Jun 27 2007(Updated: )
libdayzero.dll in the Filter Hub Service (filter-hub.exe) in Symantec Mail Security for SMTP before 5.0.1 Patch 181 and Mail Security Appliance before 5.0.0-36 allows remote attackers to cause a denial of service (crash) via a crafted executable attachment in an e-mail, involving the detection of "PE-Shield v0.2" and "ASPack v1.00-1.08.02".
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Mail Security Appliance | <=5.0.0-35 | |
Symantec Mail Security | =5.0.0 | |
Symantec Mail Security | =5.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1792 has a medium severity rating as it can cause a denial of service in the affected systems.
To fix CVE-2007-1792, upgrade to Symantec Mail Security for SMTP version 5.0.1 Patch 181 or later.
CVE-2007-1792 affects Symantec Mail Security 5.0.0 and 5.0.1 before patch 181, and the respective Mail Security Appliance prior to version 5.0.0-36.
CVE-2007-1792 is a denial of service vulnerability caused by handling crafted executable attachments.
Remote attackers can exploit CVE-2007-1792 by sending specifically crafted executable email attachments.