B&B Bezpieczeństwo w biznesie
  • Start
  • O nas
  • Produkty
  • Usługi
    • Szkolenia
    • Cyberbezpieczny Samorząd
    • Audyt bezpieczeństwa informacji
      • Testy penetracyjne
      • Testy ataków socjotechnicznych
    • Audyt konfiguracji Fortigate
    • Prezentacje
    • Wdrożenia
  • Blog techniczny
  • Pomoc
  • Kariera
  • Kontakt

Najnowsza aktualizacja dla produktu FortiMail o oznaczeniu 7.4.2 została wydana a w niej wiele poprawek i nowości. Wersja 7.4.2 nie jest już podatna na następujące odniesienia CVE/CWE: CWE-345, CWE-1395, CWE-613 oraz CVE-2023-47539. Dodano między innymi obsługę importu i eksportu grup e-mailowych i grup IP jako plików .csv, ponadto wprowadzono możliwość uwierzytelniania certyfikatów klienta w profilach LDAP. Poprawki dotknęły obszar ochrony antyspam/antywirus, naprawiono błędy dotyczące poprawnego rozpoznawania rekordów SPF, samoistnego uruchomienia ochrony kliknięć za pomocą FortiIsolator, odrzucania prawidłowych załączników .jpg oraz wiele więcej o czym można przeczytać w poniższym artykule.

Wspierane modele:

FortiMail 200F, 2000E, 2000F, 3000E, 3000F, 3200E, 400F, 900F
FortiMail VM
  • VMware vSphere Hypervisor ESX/ESXi 6.0, 6.7, 7.0 and higher
  • Microsoft Hyper-V Server 2008 R2, 2012 and 2012 R2, 2016, 2019, 2022
  • KVM qemu 2.12.1 and higher
  • Citrix XenServer v5.6sp2, 6.0 and higher; Open Source XenServer 7.4 and higher
  • Alibaba Cloud BYOL
  • AWS BYOL and On-Demand
  • Azure BYOL and On-Demand
  • Google Cloud Platform BYOL
  • Oracle Cloud Infrastructure BYOL

Rozwiązane problemy:

AntiSpam/AntiVirus

Bug ID Description
987126 Click protection with FortiIsolator occurred when its URL rating category was configured, even though CDR was not enabled in the content profile.
984945 In some case, legitimate JPG files are blocked by the content filter.
978390 Large QR codes cannot be detected.
974770 QR code with inverted colors cannot be detected.
966866 QR code scan does not detect images with transparent backgrounds.
973157 The specified recipient in the on-demand scan rule for Microsoft 365 is ignored.
955513 Enabling „Detect embedded components” in the content profile may cause system to not work properly.
985249 Fail to submit the email to FortiSandbox when the attachment ends with „.” (such as „test.htm.”).
977414 In some cases, outbound email is rejected with error „timeout before data read, where=eom”.
993514 Large dictionary with wildcards may cause high CPU usage and email rejection.
993340 In some cases, the SPF records cannot be resolved properly.
995247 Email classified as a „Sender Alignment” is not archived in the „Bulk” but in the „Inbox”.

Mail Delivery

Bug ID Description
982592 Message ID is the same for email that is sent to original host and released from system quarantine.
976027 Some email was incorrectly rejected with SMTP code 421 4.7.0 and mail event error message milter_write(mailfilterd).
959876 After upgrading to 7.4.1 from 7.2.2, if the incoming email size is bigger than the maximum size to scan defined in the antispam profile, the email will be rejected.

System

Bug ID Description
984713 4096-bit DKIM key import is not supported.
988353 SAML attribute to identify email address does not work.
955065 PKI admin login with non-ASCII characters does not work.
969925 After upgrading to v7.4.1, users cannot log in to FortiMail using RADIUS authentication.
966146 High memory usage when processing certain email.
963070 Domain administrators can change their permissions to other domains.
964861 In active-active HA mode, NFS synchronization after network disconnection overwrites data instead of appending data.
989046 Duplicate email after restoring the mailbox.
993319 In HA mode, the personal quarantine folder is automatically removed after some time on the secondary unit.
994895 In some cases, the quarantined email cannot be released from the History view.
995799 Incorrect replacement message information for email sent in HTML or Rich Text Format.
992801 LDAP synchronization for address book in server mode does not work properly.
997707 When importing contacts from the LDAP server, if a value has „” , the symbol „\\” is added,

Log and Report

Bug ID Description
962023 Logs sent via syslog miss the „Disposition” field entry when email is sent to domain quarantine.
963521 Incorrect results for „OR” search criteria in log search tasks.
992734 In some cases, the original file names are not logged when sending attachments to FortiSandbox.

Admin GUI/Webmail

Bug ID Description
960618 After upgrading to v7.4.1, the domain MTA status displays incorrectly.
972443 After the user accesses the secure email (IBE) webmail, the error message „Unable to open message. It might have been moved or deleted” displays although the secure email is showing in the inbox.
962059 After upgrading to v7.4.1, email cannot be sent to a contact name containing a comma in webmail.
973645 Webmail logins are redirected when mail migration is configured but „Enable mail migration” is disabled.
989622 Webmail unable to load when SSO is used and the webmail page is closed and then re-opened.
966184 Mail Statistics does not include email messages from associated domains.
997778 „Internal server error” message when creating an event in webmail calendar using a contact group for attendee.

Common Vulnerabilities and Exposures

Bug ID Description
988041 CWE-345: Insufficient Verification of Data Authenticity
985989 CWE-1395: Dependency on Vulnerable Third-Party Component
985968 CWE-613: Insufficient Session Expiration
959932 CVE-2023-47539: Improper Access Control

Notatki producenta: FortiMail 7.4.2

Pozdrawiamy,

Zespół B&B
Bezpieczeństwo w biznesie

Post Views: 1 250

FortiMail FortiMail 7.4.2

Poprzedni artykułFortiOS 7.0.14Następny artykuł ESET PROTECT version 5.1

Najnowsze

FortiAnalyzer 7.6.38 maja 2025
FortiManager 7.6.330 kwietnia 2025
FortiMail 7.6.322 kwietnia 2025

Kategorie

  • Acronis
  • Aktualności
  • Bez kategorii
  • ESET
  • F-Secure
  • FortiAnalyzer
  • FortiAP
  • FortiAuthenticator
  • FortiClient
  • FortiDeceptor
  • FORTIGATE
  • FORTIMAIL
  • FortiManager
  • FortiNAC
  • FortiSIEM
  • FORTISWITCH
  • FortiWeb
  • NAKIVO
  • Proget
  • Qnap
  • Stormshield
  • Szkolenia
  • Veeam
  • VMware
  • WithSecure

Tagi

6.0.6 6.2.2 6.2.7 6.4.0 6.4.4 6.4.5 6.4.8 7.0.0 7.0.2 7.0.5 7.2.0 7.2.2 ems Eset eset endpoint antivirus eset endpoint security ESET Inspect ESET Protect ESET Protect Cloud F-Secure FMG FortiAnalyzer forti analyzer FortiAP fortiap-w2 FortiAuthenticator FortiClient FortiClientEMS forticlient ems FortiGate FortiMail FortiManager FortiNAC Fortinet FortiOS FortiSIEM FortiSwitch FortiWeb vCenter vCenter Server VMware VMware ESXi vmware esxi 8.0 vmware vcenter VMware vCenter Server

MENU

  • Start
  • O nas
  • Produkty
  • Usługi
    • Szkolenia
    • Cyberbezpieczny Samorząd
    • Audyt bezpieczeństwa informacji
      • Testy penetracyjne
      • Testy ataków socjotechnicznych
    • Audyt konfiguracji Fortigate
    • Prezentacje
    • Wdrożenia
  • Blog techniczny
  • Pomoc
  • Kariera
  • Kontakt

BLOG TECHNICZNY

FortiAnalyzer 7.6.38 maja 2025
FortiManager 7.6.330 kwietnia 2025
FortiMail 7.6.322 kwietnia 2025

KONTAKT

biuro@b-and-b.plhttps://www.b-and-b.pl
8:00-16:00
RODO | POLITYKA PRYWATNOŚCI
OGÓLNE WARUNKI REKLAMACJI

BEZPIECZEŃSTWO W BIZNESIE 2025 - wszystkie prawa zastrzeżone

MENU

  • Start
  • O nas
  • Produkty
  • Usługi
    • Szkolenia
    • Cyberbezpieczny Samorząd
    • Audyt bezpieczeństwa informacji
      • Testy penetracyjne
      • Testy ataków socjotechnicznych
    • Audyt konfiguracji Fortigate
    • Prezentacje
    • Wdrożenia
  • Blog techniczny
  • Pomoc
  • Kariera
  • Kontakt

BLOG TECHNICZNY

FortiAnalyzer 7.6.38 maja 2025
FortiManager 7.6.330 kwietnia 2025
FortiMail 7.6.322 kwietnia 2025

Kontakt

+48 500-413-313
biuro@b-and-b.pl
8:00-16:00
Add new entry logo

Korzystamy z plików cookies lub podobnych technologii, by lepiej dopasować treści na stronie do Twoich potrzeb. W każdej chwili możesz zmienić ustawienia cookies. Polityka prywatności

Akceptuję Odmów
Cookies are small text files that can be used by websites to make a user's experience more efficient. The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission. This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.
  • Always Active
    Necessary
    Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.

  • Marketing
    Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.

  • Analytics
    Analytics cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.

  • Preferences
    Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.

  • Unclassified
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.