Published:2012/09/20  Last Updated:2012/09/20

JVN#50701493
Email Anti-virus (formerly WebShield SMTP) vulnerable to denial-of-service

Overview

Email Anti-virus (formerly WebShield SMTP) provided by McAfee Co., Ltd. contains a denial-of-service (DoS) vulnerability.

Products Affected

  • Email Anti-virus (formerly WebShield SMTP)

Description

Email Anti-virus (formerly WebShield SMTP) provided by McAfee Co., Ltd. is an anti-virus package that scans emails. Email Anti-virus (formerly WebShield SMTP) contains a denial-of-service (DoS) vulnerability.

Impact

An attacker may be able to cause a denial-of-service (DoS).

Solution

Do not use Email Anti-virus (formerly WebShield SMTP)
Please stop use of Email Anti-virus (formerly WebShield SMTP) according to the information provided by the developer.
The developer has stopped supporting the product.

Vendor Status

Vendor Link
McAfee Co., Ltd. McAfee Product & Technology Support Lifecycle

References

JPCERT/CC Addendum

This JVN publication was delayed to 2012/09/20 after the developer fix was developed. From the fiscal year 2011, JPCERT/CC is using a new vendor coordination procedure. This new procedure came from the recommendation of the fiscal year 2010 "Study Group on Information System Vulnerability Handling" aimed at more timely JVN publications.

Vulnerability Analysis by JPCERT/CC

Credit

IGARASHI Eiichi of New Media Research Institute Co., Ltd. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2012-4014
JVN iPedia JVNDB-2012-000086