Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Mail Security causing Nessus "Microsoft Exchange X-LINK2STATE Heap Overflow PoC"?

Created: 08 Sep 2010 | 8 comments
NonameNick's picture
0 0 Votes
Login to vote

Hello,

I have a nessus report (hackersafe) stating that a vulnerability exists: "Microsoft Exchange X-LINK2STATE Heap Overflow PoC". The w2k3 machine (exchange 2k3) is fully patched, as is exchange. I google search revealed someone else with a similar issue.

Does anyone know if this is caused by Symantec mail security? I'm running version 6..5.0.67

Thanks!

discussion Filed Under:

Comments

TSE-JDavis's picture
08
Sep
2010
1 Vote +1
Login to vote

On Exchange 2003 we register

On Exchange 2003 we register as an eventsink with the SMTP service, so it is possible that Nessus is detecting something.

All indications I am getting from our backline team is that this should be fixed in SP1 of Server 2003

NonameNick's picture
08
Sep
2010
0 Votes 0
Login to vote

My version is...

6.5 (7638.2) SP2. As far as I can see, there are no updates available from MS for this version. I suppose the only way to test is to remove and re-install?

Thanks,
Nick.

Mahesh Roja's picture
09
Sep
2010
0 Votes 0
Login to vote

Have you applied

All the microsoft patches, windows update and install all the security patches

If this Info helps to resolve the issue please Mark as Solution

Thanks

NonameNick's picture
10
Sep
2010
0 Votes 0
Login to vote

Yes, fully patched on MS

Yes, fully patched on MS Update. I was under the impression that the error in question was resolved in exchange sp2, which I'm running.

 

N.

TSE-JDavis's picture
10
Sep
2010
1 Vote +1
Login to vote

The SMTP service on Server

The SMTP service on Server 2003 is not part of Exchange. It is part of the OS. Exchange just integrates with it.

 

If you were to try removing that service from Add/Remove programs, and then install Exchange, you will get errors.

NonameNick's picture
10
Sep
2010
0 Votes 0
Login to vote

So is the general consensus

So is the general consensus that this issue is not caused by Mail Security? I would have thought this would be a known issue, so I'm thinking perhaps it is something else on that machine (although no idea what, as there isn't much on it).

TSE-JDavis's picture
13
Sep
2010
1 Vote +1
Login to vote

Not at all Nick, we are

Not at all Nick, we are waiting for you to tell us if removing SMSMSE fixed the warning. If so, you will need to open a ticket with support so our backline engineers can investigate this.

NonameNick's picture
14
Sep
2010
0 Votes 0
Login to vote

I uninstalled mail security,

I uninstalled mail security, but the issue still  occurred. So it isn't symantec's mail security product. Thanks!