「GUARDIANWALL MailSuite」におけるスタックベースのバッファオーバーフローの脆弱性について(JVN#35567473)

Imported from official source

Announcement

キヤノンマーケティングジャパン株式会社が提供する「GUARDIANWALL MailSuite」はメールセキュリティ製品です。

「GUARDIANWALL MailSuite(オンプレミス版)」及び「GUARDIANWALL Mailセキュリティ・クラウド(SaaS版)」にはスタックベースのバッファオーバーフローの脆弱性が存在します。

攻撃者によって当該製品のWebサービスに細工されたリクエストを送信された場合、任意のコードを実行される可能性があります。

開発者によると、GUARDIANWALL MailSuite(オンプレミス版)において本脆弱性を悪⽤した攻撃が既に確認されているとのことです。

GUARDIANWALL MailSuite(オンプレミス版)Ver 1.4.00からVer 2.4.26まで

GUARDIANWALL Mailセキュリティ・クラウド(SaaS版)2026年4⽉30⽇のメンテナンスより前のバージョン

なお、GUARDIANWALL Mailセキュリティ・クラウド(SaaS版)は2026年4⽉30⽇のメンテナンスで修正済みです。

開発者はパッチを適⽤するまでの間、ワークアラウンドの適⽤を推奨しています。
詳細は、開発者が提供する情報を確認してください。

This is an extract. The publication continues at the source.

Read the original at the source: https://www.ipa.go.jp/security/security-alert/2026/20260513-jvn.html

Officially imported this from Information-technology Promotion Agency (IPA)’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Information-technology Promotion Agency (IPA) — imported from official source
Official source
https://www.ipa.go.jp/security/alert-rss.rdf RSS
Imported
October 03, 2026 20:39
Versions
1 recorded
Identity
https://www.ipa.go.jp/security/security-alert/2026/20260513-jvn.html

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.