Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Symantec Product Vulnerabilities and Internet Email Scanning feature

Updated: 24 Jun 2011 | 1 comment
Andy Chow's picture
0 0 Votes
Login to vote

A vulnerability has been reported in multiple Symantec products.

http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090826_01

From what I gathered, the mitigation against this exploitation is to disable the Internet Email Scanning. (This feature is currently enabled in our environment)

Some questions before we consider this mitigation approach.
1. What does Internet Email Scanning feature does in the first place? Does it scan emails that comes from Gmail, Yahoo? Or Emails from coming Microsoft Outlook Express?

2. We are using Lotus Notes as our primarily email client. Is this Internet Email Scanning feature necessary for our existing email client?

3. Anyone know if there is any description about the exploit for this vulnerability. I want to check with my Anti-Spam provider whether they have any signatures that is capable of blocking this exploit.

Regards,
AC

Comments

Rafeeq's picture
01
Sep
2009
1 Vote +1
Login to vote

Hi

What does Internet Email Scanning feature does in the first place? Does it scan emails that comes from Gmail, Yahoo? Or Emails from coming Microsoft Outlook Express?

Internet Email Auto-Protect protects both incoming email messages and outgoing email messages that use the POP3 or SMTP communications protocol over the Secure Sockets Layer (SSL). When Internet Email Auto-Protect is enabled, the client software scans both the body text of the email and any attachments that are included

Email scanning does not support the following email clients:

IMAP clients

AOL clients

HTTP-based email such as Hotmail and Yahoo! Mail

File System Auto-Protect scans email attachments when you save the attachments to the hard drive

2)We are using Lotus Notes as our primarily email client. Is this Internet Email Scanning feature necessary for our existing email client?

Yes
By default, Auto-Protect scans Lotus Notes email attachments

3) Anyone know if there is any description about the exploit for this vulnerability. I want to check with my Anti-Spam provider whether they have any signatures that is capable of blocking this exploit

So far
Symantec is not aware of any customers impacted by this issue, or of any attempts to exploit the issue.

 

Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq