Release date:
Updated on:
Affected Systems:
McAfee Email Gateway 7.0 Patch 1
McAfee Email Gateway 7.0
Unaffected system:
McAfee Email Gateway 6.7.2 Hotfix 2
McAfee Email Gateway 6.7.2 Hotfix 1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 63544
CVE (CAN) ID: CVE-2013-6349
McAfee Email Gateway is a comprehensive Email security solution.
If the graphic user interface of McAfee Email Gateway 7.0-7.0.3 and McAfee Email Gateway 7.5-7.5.0 receives the specific data directly sent, any shell command is executed, attackers can obtain root-level superuser access permissions. A valid session ID is required to exploit this vulnerability.
<* Source: ANZ Bank
Link: http://osvdb.org/98669
Https://kc.mcafee.com/corporate/index? Page = content & id = SB10057
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
McAfee
------
McAfee has released a Security Bulletin (SB10057) for this purpose and corresponding patches:
SB10057: McAfee Security Bulletin-Email Gateway privilege escalation issue patched
Link: https://kc.mcafee.com/corporate/index? Page = content & id = SB10057
Patch download: http://www.mcafee.com/us/downloads