PT-2012-5593 · Microsoft · Exchange Server
Publicado
2012-12-11
·
Atualizado
2019-06-01
·
CVE-2012-4791
CVSS v2.0
3.5
Baixa
| Vetor | AV:N/AC:M/Au:S/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Exchange Server versions 2007 SP3 through 2010 SP2
Description
A denial of service issue exists due to improper handling of RSS feeds, which could cause the Information Store service to become unresponsive. This condition may lead to Exchange databases dismounting and potentially result in database corruption, affecting user mailboxes.
Recommendations
For Microsoft Exchange Server versions 2007 SP3 through 2010 SP2, consider disabling the RSS feed subscription feature as a temporary workaround until a patch is available. Restrict access to crafted RSS feeds to minimize the risk of exploitation.
Correção
DoS
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Exchange Server