製品・ソフトウェアに関する情報
McAfee Email などにおける任意のファイルを読み取られる脆弱性
Title McAfee Email などにおける任意のファイルを読み取られる脆弱性
Summary

McAfee Email および Web Security Appliance VMtrial には、任意のファイルを読み取られる脆弱性が存在します。

Possible impacts 第三者により、任意のファイルを読み取られる可能性があります。
Solution

ベンダ情報および参考情報を参照して適切な対策を実施してください。

Publication Date Sept. 24, 2009, midnight
Registration Date Sept. 25, 2012, 5:27 p.m.
Last Update Sept. 25, 2012, 5:27 p.m.
CVSS2.0 : 危険
Score 7.8
Vector AV:N/AC:L/Au:N/C:C/I:N/A:N
Affected System
マカフィー
McAfee Email and Web Security Appliance 5.1
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
Change Log
No Changed Details Date of change
0 [2012年09月25日]
  掲載
Feb. 17, 2018, 10:37 a.m.

NVD Vulnerability Information
CVE-2009-3339
Summary

Unspecified vulnerability in McAfee Email and Web Security Appliance 5.1 VMtrial allows remote attackers to read arbitrary files via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

Summary

Per http://www.mcafee.com/us/enterprise/products/virtualization_security/email_and_web_security_appliance_virtual.html

Experience McAfee Email and Web Security Appliance through the power of virtualization

We’ve made it easier than ever to evaluate McAfee Email and Web Security Appliance, our email and web security appliance. Thanks to VMware virtualization technology, you can download a free 30-day software trial—with all of the features and functionality of the appliance. Install it on your server and experience uncompromising protection against spam, phishing, viruses, spyware, and more.

Publication Date Sept. 25, 2009, 1:30 a.m.
Registration Date Jan. 29, 2021, 1:23 p.m.
Last Update Sept. 28, 2009, 1 p.m.
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:a:mcafee:email_and_web_security_appliance:5.1:-:vmtrial:*:*:*:*:*
execution environment
1 cpe:2.3:h:mcafee:email_and_web_security_appliance:*:*:*:*:*:*:*:*
Related information, measures and tools
Common Vulnerabilities List