PT-2002-2666 · Smartmail · Smartmail Server

Published

2002-12-31

·

Updated

2008-09-05

·

CVE-2002-1945

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions SmartMail Server version 1.0 Beta 10
Description The issue allows remote attackers to cause a denial of service, resulting in a crash, by sending a long request to either the SMTP or POP3 service. Specifically, this can be achieved through "TCP port 25 (SMTP)" or "TCP port 110 (POP3)".
Recommendations For SmartMail Server version 1.0 Beta 10, consider restricting access to TCP ports 25 and 110 until a patch is available to prevent potential denial of service attacks.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1945

Affected Products

Smartmail Server