PT-2006-3087 · Bl4 · Bl4 Smtp Server

Dedi Dwianto

·

Published

2006-04-29

·

Updated

2018-10-18

·

CVE-2006-2107

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions BL4 SMTP Server versions 0.1.4 and earlier
Description The issue allows remote attackers to cause a denial of service or execute arbitrary code via a long argument to the (1) EHLO, (2) MAIL FROM, and (3) RCPT TO commands.
Recommendations For versions 0.1.4 and earlier, consider disabling the EHLO, MAIL FROM, and RCPT TO commands until a patch is available to prevent potential exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2107

Affected Products

Bl4 Smtp Server