PT-2005-2154 · Kerio · Kerio Mailserver

Published

2005-04-16

·

Updated

2008-09-05

·

CVE-2005-1138

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Kerio MailServer versions prior to 6.0.9
Description A security issue in Kerio MailServer's WebMail service allows remote attackers to cause a denial of service by consuming excessive CPU resources or crashing the service. This can be achieved by sending specially crafted e-mail messages to the target user, which when viewed using the WebMail service, exploits the issue. The estimated number of potentially affected devices worldwide is not available.
Recommendations For versions prior to 6.0.9, update to version 6.0.9 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1138

Affected Products

Kerio Mailserver