Note: This is an archival copy of Security Sun Alert 201180 as previously published on http://sunsolve.sun.com.
Latest version of this security advisory is available from http://support.oracle.com as Sun Alert 1000892.1.
Article ID : 1000892.1
Article Type : Sun Alerts (SURE)
Last reviewed : 2010-01-24
Audience : PUBLIC
Copyright Notice: Copyright © 2010, Oracle Corporation and/or its affiliates.

Security Vulnerability Involving Webmail



Category
Security

Release Phase
Resolved

Bug Id
5072113

Date of Resolved Release
08-NOV-2004

Impact

A security vulnerability in iPlanet Messaging Server/Sun ONE Messaging web-based e-mail may allow a remote unprivileged user the ability to gain unauthorized access to a webmail user's e-mail using a specially crafted e-mail message.

Sun acknowledges, with thanks, Ramon Pinuaga Cascales of s21sec.com for bringing this issue to our attention.


Contributing Factors

This issue can occur in the following releases:

SPARC Platform

  • iPlanet Messaging Server 5.2 (for Solaris 2.6 and Solaris 8) without patch 5.2hf2.02
  • Sun ONE Messaging Server 6.1 (for Solaris 8 and Solaris 9) without patch 116568-55

x86 Platform

  • Sun ONE Messaging Server 6.1 (for Solaris 9) without patch 116569-55

Linux

  • Sun ONE Messaging Server 6.1 (for RHEL 2.1) without patch 117758-04

Notes:

  1. iPlanet Messaging Server 5.2 is not supported on Solaris 7.
  2. Sun ONE Messaging Server 6.1 is not supported on Solaris 7 or Solaris 8 on the x86 platform.

Symptoms

There are no reliable symptoms that would show the described issue has been exploited.


Workaround

There is no workaround. Please see the "Resolution" section below.


Resolution

This issue is addressed in the following releases:

SPARC Platform

  • iPlanet Messaging Server 5.2 (for Solaris 2.6 and Solaris 8) with patch 5.2hf2.02 or later
  • Sun ONE Messaging Server 6.1 (for Solaris 8 and 9) with patch 116568-55 or later

x86 Platform

  • Sun ONE Messaging Server 6.1 (for Solaris 9) with patch 116569-55 or later

Linux

  • Sun ONE Messaging Server 6.1 (for RHEL 2.1) with patch 117758-05 or later

Note: iPlanet Messaging Server 5.2 patch 5.2hf2.02 is available through normal support channels.



Modification History

Product
iPlanet Messaging Server 5.2

References

116568-55
116569-55
117758-05





Attachments
This solution has no attachment