SMTP: MIME Filename Directory Traversal

This signature detects Multipurpose Internet Mail Extensions (MIME) attachments with directory traversal characters in their filenames. Malicious users can utilize this method to place executable files onto a target system.

Extended Description

MDaemon server is prone to a directory traversal vulnerability due to improper sanitization of user input. Failure to sanitize the filename and path may result in compromise of the file system outside of the application's quarantine directory.

Affected Products

Alt-n mdaemon

Short Name
SMTP:EXT:DIR-TRAV
Severity
Minor
Recommended
False
Recommended Action
None
Category
SMTP
Keywords
CVE-2002-1741 Directory Filename MIME Traversal bid:14400
Release Date
10/05/2005
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Alt-n

CVSS Score

7.2

Found a potential security threat?