PT-2002-2666 · Smartmail · Smartmail Server
Published
2002-12-31
·
Updated
2008-09-05
·
CVE-2002-1945
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
SmartMail Server version 1.0 Beta 10
Description
The issue allows remote attackers to cause a denial of service, resulting in a crash, by sending a long request to either the SMTP or POP3 service. Specifically, this can be achieved through "TCP port 25 (SMTP)" or "TCP port 110 (POP3)".
Recommendations
For SmartMail Server version 1.0 Beta 10, consider restricting access to TCP ports 25 and 110 until a patch is available to prevent potential denial of service attacks.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Smartmail Server