PT-2002-2841 · Surfcontrol · Surfcontrol Superscout Email Filter For Smtp

Published

2002-12-31

·

Updated

2016-10-18

·

CVE-2002-2121

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: SurfControl SuperScout Email filter for SMTP version 3.5.1
Description: The issue allows remote attackers to cause a denial of service, resulting in a crash, by sending a long SMTP command, specifically the (1) HELO or (2) RCPT TO command. This could be due to a buffer overflow.
Recommendations: For version 3.5.1, consider restricting the length of incoming SMTP commands to prevent the denial of service. As a temporary workaround, limiting the size of the HELO and RCPT TO commands may help mitigate the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-2121

Affected Products

Surfcontrol Superscout Email Filter For Smtp