Symantec Messaging Gateway information leakage (CVE-2016-2203)
Symantec Messaging Gateway information leakage (CVE-2016-2203)
Release date:
Updated on:
Affected Systems:
Symantec Messaging Gateway <10.6.1
Description:
Bugtraq id: 86137
CVE (CAN) ID: CVE-2016-2203
Symantec Messaging Gateway is Symantec's email virus protection software.
Symantec Messaging Gateway (SMG) earlier than Appliance 10.6.1 has a security vulnerability in the management console. Local users can obtain the encrypted AD password through certain read permissions.
<* Source: karim reda Fakhir
Link: https://www.symantec.com/security_response/securityupdates/detail.jsp? Fid = security_advisory & pvid = sec
*>
Suggestion:
Vendor patch:
Symantec
--------
Symantec has released a Security Bulletin (SYM16-005) and patches for this:
SYM16-005: Symantec Messaging Gateway Multiple Security Issues
Link: https://www.symantec.com/security_response/securityupdates/detail.jsp? Fid = security_advisory & pvid = sec
This article permanently updates the link address: