发布时间 :2006-04-04 10:04:00
修订时间 :2017-07-19 21:29:52

[原文]Format string vulnerability in the SMTP server for McAfee WebShield 4.5 MR2 and earlier allows remote attackers to execute arbitrary code via format strings in the domain name portion of a destination address, which are not properly handled when a bounce message is constructed.

[CNNVD]McAfee Webshield SMTP 远程格式化字符串漏洞(CNNVD-200604-031)

        McAfee WebShield SMTP是基于软件而独立于防火墙的扫描程序,可以方便地接入到几乎任何网络中。
        McAfee WebShield SMTP的用于创建不存在域返回消息的函数中存在格式串处理漏洞,远程攻击者可能利用此漏洞在服务器上执行任意指令。

- CVSS (基础分值)

CVSS分值: 10 [严重(HIGH)]
- 官方数据库链接
(官方数据源) MITRE
(官方数据源) NVD
(官方数据源) CNNVD

- 其它链接及资源
(VENDOR_ADVISORY)  BUGTRAQ  20060404 SYMSA-2006-002: McAfee WebShield SMTP Format String Vulnerability
(PATCH)  BID  16742
(UNKNOWN)  VUPEN  ADV-2006-1219
(UNKNOWN)  XF  webshield-smtp-format-string(25621)

- 漏洞信息

McAfee Webshield SMTP 远程格式化字符串漏洞
危急 格式化字符串
2006-04-04 00:00:00 2006-04-05 00:00:00
- 公告与补丁


McAfee WebShield SMTP Bounce Message Format String
Remote / Network Access, Local / Remote, Context Dependent Input Manipulation
Loss of Integrity

WebShield SMTP contains a flaw that may allow a malicious user to execute arbitrary code. The issue is triggered due to a format string error within the construction of bounce messages for non-existent domains. It is possible that the flaw may allow remote code execution resulting in a loss of integrity.

2006-04-03 Unknow
Unknow Unknow

Upgrade to version 4.5 MR2 or higher, as it has been reported to fix this vulnerability. In addition, the vendor has released a patch for some older versions.

McAfee Webshield SMTP Remote Format String Vulnerability
Input Validation Error 16742
Yes No
2006-04-03 12:00:00 2007-06-27 09:28:00
Ollie Whitehouse <> of Symantec Consulting Services discovered this vulnerability.

McAfee WebShield SMTP 4.5 MR1a
McAfee WebShield SMTP 4.5 MR2

McAfee WebShield SMTP 4.5 MR2

McAfee WebShield SMTP is susceptible to a remote format-string vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input before including it in a format-specifier argument to a formatted-printing function.

This issue allows remote attackers to execute arbitrary machine code in the context of the affected application.

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at:

The vendor has released a patch (P0803), along with version 4.5 MR2 to address this issue. Users of affected packages should contact the vendor for information on obtaining fixes.

