1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Security Advisory FSC-2009-2

Mail relay vulnerability

Date issued 2009-06-16
Last updated 2009-06-16
Risk level Medium (Low/Medium/High/Critical)
Brief description Specially crafted messages may be used to bypass mail relay restrictions.
Mitigating factors
  • The issue only affects systems where the SMTP Turbo module is used for mail distribution.
  • Incorrectly relayed messages still pass through spam filtering, which decreases the vulnerability’s usefulness for spam relaying.
Affected platforms All supported platforms
Products F-Secure Messaging Security Gateway 5.5.x
Risk level Medium
Notes An external attacker can use affected systems as mail relay by using specially crafted SMTP messages. A patch for the problem has been distributed to affected systems. The patch will be installed automatically or wait for the administrator’s approval depending on system settings. Administrators are urged to approve installation of patch 739 without delay, or verify that automatic installation of this patch has succeeded.
Advisory location: http://www.f-secure.com/en_EMEA/support/security-advisory/fsc-2009-2.html

Available patches:

F-Secure deliver patches to its supported product versions that are vulnerable. See further information on supported products and F-Secure’s Product Lifecycle Policy.

Product Versions Download
F-Secure Messaging Security Gateway 5.5.x Fix available in the update channel
Revision history FSC-2009-06-16

Contact information:
Support: http://www.f-secure.com/en_EMEA/support/
URL: http://www.f-secure.com/