<> Trend Micro Incorporated August 6th, 2020 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Trend Micro(TM) ScanMail for IBM Domino 5.8 - GM English - Windows - 64 Bits Critical Patch - Build 1070 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Contents ========================================================== 1. Overview of This Critical Patch Release 1.1 Issues 1.2 Files Included in This Release 2. Documentation Set 3. System Requirements 4. Installation 4.1 Installing 4.2 Uninstalling 5. Post-installation Configuration 6. Known Issues 7. Release History 8. Contact Information 9. About Trend Micro 10. License Agreement ========================================================== 1. Overview of This Critical Patch Release ======================================================================== 1.1 Issues ===================================================================== This critical patch resolves the following issue: Issue 1: A directory traversal vulnerability occurs when ScanMail downloads engine files or pattern files from the local ActiveUpdate (AU) server. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Solution 1: This critical patch updates the Trend Micro ActiveUpdate modules to resolve this issue. 1.2 Files Included in This Release ===================================================================== A. Files for Current Issue --------------------------------------------------------------------- Files for Issue 1 ------------------------------------------------------------------ Filename Build No. -------------------------------------------------------------------- nSMDupd.dll 5.8.0.1070 nSMDcm.dll 5.8.0.1070 nSMDdbs.dll 5.8.0.1070 nSmdDTAS.dll 5.8.0.1070 nSMDemf.dll 5.8.0.1070 nSMDeuq.dll 5.8.0.1070 nSMDext.dll 5.8.0.1070 nSMDreal.dll 5.8.0.1070 nSMDsch.dll 5.8.0.1070 nSMDmon.dll 5.8.0.1070 nupdsmd.dll 5.8.0.1070 nSMDsupp.dll 5.8.0.1070 ProductLib.dll 5.8.0.1070 UnregCMLib.dll 5.8.0.1070 UnregCM.exe 5.8.0.1070 nBIFSender.exe 5.8.0.1070 nloader.exe 5.8.0.1070 smconf.ntf 5.8.0.1070 smdapproved.ntf 5.8.0.1070 smddtas.ntf 5.8.0.1070 smency.ntf 5.8.0.1070 smftypes.nsf 5.8.0.1070 smhelp.nsf 5.8.0.1070 smlists.nsf 5.8.0.1070 smmsg.nsf 5.8.0.1070 smquar.ntf 5.8.0.1070 smtime.ntf 5.8.0.1070 smvlog.ntf 5.8.0.1070 AU module Files ------------------------------------------------------------------ cert5.db 2.86.4002 ciuas64.dll 2.86.4002 ciussi64.dll 2.86.4002 patch64.exe 2.86.4002 patchw64.dll 2.86.4002 TmUpdate64.dll 2.86.4002 x500.db 2.86.4002 MCP AgentSDK Files ------------------------------------------------------------------ En_BlobConvertUtility.dll 5.0.0.2363 En_I18N.dll 5.0.0.2363 En_Utility.dll 5.0.0.2363 libapr-1.dll 5.0.0.2363 libcurl.dll 5.0.0.2363 libeay32.dll 5.0.0.2363 ssleay32.dll 5.0.0.2363 SSO_PKIHelper.dll 5.0.0.2363 TrendAprWrapperDll.dll 5.0.0.2363 zlibwapi.dll 5.0.0.2363 PR Files ------------------------------------------------------------------ TmPrApi.dll 1.2.0.1158 TmPrApiD.dll 1.2.0.1158 TmPrApiT.dll 1.2.0.1158 TmPrApiTD.dll 1.2.0.1158 eManager module Files ------------------------------------------------------------------ adj.dat 7.6.0.1283 adj.idx 7.6.0.1283 adv.dat 7.6.0.1283 adv.idx 7.6.0.1283 american-name.txt 7.6.0.1283 cme.conf 7.6.0.1283 cme_dll.dll 7.6.0.1283 cme_vxe_dll.dll 7.6.0.1283 data_dna.dll 7.6.0.1283 DlpEngine.dll 7.6.0.1283 dtengine64.dll 7.6.0.1283 emDebug.dll 7.6.0.1283 em_expression.dll 7.6.0.1283 em_helpr.dll 7.6.0.1283 em_synonym.dll 7.6.0.1283 etyv 7.6.0.1283 icudt57.dll 7.6.0.1283 icuin57.dll 7.6.0.1283 icuuc57.dll 7.6.0.1283 BPMNT.dll 7.6.0.1283 vsapi64.dll 7.6.0.1283 noun.dat 7.6.0.1283 noun.idx 7.6.0.1283 Policy.xml 7.6.0.1283 pthreadVC2.dll 7.6.0.1283 spanish-name.txt 7.6.0.1283 tmpe.pol 7.6.0.1283 tmpeEnum.xml 7.6.0.1283 verb.dat 7.6.0.1283 verb.idx 7.6.0.1283 B. Files for Previous Issues --------------------------------------------------------------------- Not applicable. 2. Documentation Set ======================================================================== To download or view electronic versions of the documentation set for this product, go to http://docs.trendmicro.com In addition to this Readme file, the documentation set for this product includes the following: - Online Help: The Online Help contains an overview of features and key concepts, and information on configuring and maintaining ScanMail for IBM Domino. To access the Online Help, go to http://docs.trendmicro.com - Administrator's Guide (AG): The Administrator's Guide contains an overview of features and key concepts, and information on configuring and maintaining ScanMail for IBM Domino. - Support Portal: The Support Portal contains information on troubleshooting and resolving known issues. To access the Support Portal, go to https://success.trendmicro.com 3. System Requirements ======================================================================== Trend Micro ScanMail for IBM Domino 5.8 GM Build 1024 - English - Windows - x64 4. Installation ======================================================================== This section explains key steps for installing the critical patch. 4.1 Installing ===================================================================== To install: 1. Copy the installation file "smid_58_win64_en_criticalpatch1070.exe" to a local folder. 2. Double-click the installation file. The setup screen appears. 3. Click "Install" on the setup screen. 4. Verify whether the setup was successful on the installation report screen. 5. Click "OK" to exit the setup screen. 4.2 Uninstalling ===================================================================== To roll back to the previous build: 1. Close all active IBM Notes(TM) clients and account sessions. 2. Browse to the ":\Program Files\Trend Micro\ScanMail for Domino\Hotfix\B1070" folder. 3. Run "uninstall.bat". 5. Post-Installation Configuration ======================================================================== No post-installation steps are required. NOTE: Trend Micro recommends that you update your scan engine and virus pattern files immediately after installing the product. 6. Known Issues ======================================================================== There are no known issues for this Hotfix release. 7. Release History ======================================================================== For more information about updates to this product, go to: http://www.trendmicro.com/download 8. Contact Information ======================================================================== A license to Trend Micro software usually includes the right to product updates, pattern file updates, and basic technical support for one (1) year from the date of purchase only. After the first year, you must renew Maintenance on an annual basis at Trend Micro's then-current Maintenance fees. Contact Trend Micro via fax, phone, and email, or visit our website to download evaluation copies of Trend Micro products. https://www.trendmicro.com/en_us/contact.html NOTE: This information is subject to change without notice. 9. About Trend Micro ======================================================================== Smart, simple, security that fits As a global leader in IT security, Trend Micro develops innovative security solutions that make the world safe for businesses and consumers to exchange digital information. Copyright 2020, Trend Micro Incorporated. All rights reserved. Trend Micro, ScanMail, and the t-ball logo are trademarks of Trend Micro Incorporated and are registered in some jurisdictions. All other marks are the trademarks or registered trademarks of their respective companies. 10. License Agreement ======================================================================== View information about your license agreement with Trend Micro at: https://www.trendmicro.com/en_us/about/legal.html Third-party licensing agreements can be viewed: - By selecting the "About" option in the application user interface - By referring to the "Legal" page of the Administrator's Guide