Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Eliteboy

#35093de 53,630
7.5CVSS total
Vulnerabilidades · 1
PT-2007-5621
7.5
2007-08-21
Mercury · Mercury Mail Transport System · CVE-2007-4440
**Name of the Vulnerable Software and Affected Versions** Mercury Mail Transport System versions prior to 4.51 **Description** The issue is a stack-based buffer overflow in the MercuryS SMTP server, which can be exploited by remote attackers to execute arbitrary code. This is achieved by sending a long AUTH CRAM-MD5 string. **Recommendations** For versions prior to 4.51, consider disabling the AUTH CRAM-MD5 authentication mechanism until a patch is available to prevent exploitation of the buffer overflow.