Title: NTMail v3 SPAM Relay Vulnerability
Severity: MODERATE
Description:
NTMail v3.X is susceptible to being used as a mail relay for SPAM or other unsolicited email. Connecting to the mail server (tcp25) and issuing a 'mail from' command with <> as the data will allow an unathorized user to relay email via this server.
Gordano's own JUCE product (to prevent mail relay attacks and other SPAM activity) will not prevent NTMAIL v.3.x from being used as a mail relay.
Affected Products:
- Gordano NTMail 3.0.0x
- Gordano NTMail 5.0.0e, g
References:
- Geo. <georger@nls.net>: NTMail 3 open relay
- John Stanners <john.stanners@NTMAIL.CO.UK>: Re: NTMail 3 open relay
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.