PT-2000-1916 · Microsoft · Exchange Server

Published

2000-12-11

·

Updated

2020-04-09

·

CVE-2000-1006

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Exchange Server version 5.5
Description The issue arises from improper handling of a MIME header with a blank charset specified, allowing remote attackers to cause a denial of service via a charset="" command.
Recommendations For Microsoft Exchange Server version 5.5, consider restricting access to prevent remote attackers from exploiting the issue until a proper fix is applied. As a temporary workaround, avoid using blank charsets in MIME headers to minimize the risk of denial of service attacks.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-1006

Affected Products

Exchange Server