Mail Security causing Nessus "Microsoft Exchange X-LINK2STATE Heap Overflow PoC"?
Created: 08 Sep 2010 | 8 comments
Hello,
I have a nessus report (hackersafe) stating that a vulnerability exists: "Microsoft Exchange X-LINK2STATE Heap Overflow PoC". The w2k3 machine (exchange 2k3) is fully patched, as is exchange. I google search revealed someone else with a similar issue.
Does anyone know if this is caused by Symantec mail security? I'm running version 6..5.0.67
Thanks!
discussion Filed Under:
Comments
On Exchange 2003 we register
On Exchange 2003 we register as an eventsink with the SMTP service, so it is possible that Nessus is detecting something.
All indications I am getting from our backline team is that this should be fixed in SP1 of Server 2003
My version is...
6.5 (7638.2) SP2. As far as I can see, there are no updates available from MS for this version. I suppose the only way to test is to remove and re-install?
Thanks,
Nick.
Have you applied
All the microsoft patches, windows update and install all the security patches
If this Info helps to resolve the issue please Mark as Solution
Thanks
Yes, fully patched on MS
Yes, fully patched on MS Update. I was under the impression that the error in question was resolved in exchange sp2, which I'm running.
N.
The SMTP service on Server
The SMTP service on Server 2003 is not part of Exchange. It is part of the OS. Exchange just integrates with it.
If you were to try removing that service from Add/Remove programs, and then install Exchange, you will get errors.
So is the general consensus
So is the general consensus that this issue is not caused by Mail Security? I would have thought this would be a known issue, so I'm thinking perhaps it is something else on that machine (although no idea what, as there isn't much on it).
Not at all Nick, we are
Not at all Nick, we are waiting for you to tell us if removing SMSMSE fixed the warning. If so, you will need to open a ticket with support so our backline engineers can investigate this.
I uninstalled mail security,
I uninstalled mail security, but the issue still occurred. So it isn't symantec's mail security product. Thanks!
Would you like to reply?
Login or Register to post your comment.