Mercury/32 v4.52 is a security patch release, addressing a serious weakness in the MercuryS SMTP server (specifically, a buffer overflow vulnerability in the way the server processes the AUTH command). All v4.x versions of Mercury earlier than v4.52 are vulnerable to this exploit, and users should regard the upgrade to v4.52 as mandatory.
V4.52 also fixes and extends the "Save attachment to file" filtering rule action (the "Set" button now works correctly, and you can now specify either a filename or a directory as the destination for the rule), and corrects a problem in the IMAP server where attempts to create folders using characters outside the supported character set might cause crashes.
A patched version of MercuryS suitable for use in Mercury v4.01c systems is available at the patch section as well as a patch for Mercury/NLM adressing the security issue with the MercuryS AUTH exploit for sites who do not wish to upgrade to v4.5, but we strongly urge making the move to v4.5x as soon as possible.
The feature set for v4.52 is the same as for v4.51, the release information for which is at: http://community.pmail.com/pmail/MercuryReleaseNotes.aspx
<P>Mercury/32 v4.52 is a security patch release, addressing a serious weakness in the MercuryS SMTP server (specifically, a buffer overflow vulnerability in the way the server processes the AUTH command). All v4.x versions of Mercury earlier than v4.52 are vulnerable to this exploit, and users should regard the upgrade to v4.52 as mandatory.</P>
<P>V4.52 also fixes and extends the "Save attachment to file" filtering rule action (the "Set" button now works correctly, and you can now specify either a filename or a directory as the destination for the rule), and corrects a problem in the IMAP server where attempts to create folders using characters outside the supported character set might cause crashes. </P>
<P>A patched version of MercuryS suitable for use in Mercury v4.01c systems is available at <A class="" href="http://community.pmail.com/files/folders/patches/default.aspx" mce_href="/files/folders/patches/default.aspx">the patch section</A> as well as a patch for Mercury/NLM adressing the security issue with the MercuryS AUTH exploit for sites who do not wish to upgrade to v4.5, <STRONG>but we strongly urge making the move to v4.5x as soon as possible</STRONG>.</P>
<P>The feature set for v4.52 is the same as for v4.51, the release information for which is at: <A href="http://community.pmail.com/pmail/MercuryReleaseNotes.aspx">http://community.pmail.com/pmail/MercuryReleaseNotes.aspx</A></P>