PT-2007-1317 · Mercury · Mercur Messaging 2005
Published
2007-02-23
·
Updated
2017-07-29
·
CVE-2006-7038
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
MERCUR Messaging 2005 versions prior to Service Pack 4
Description
The issue is related to multiple buffer overflows that can cause a denial of service, resulting in a crash. This can be triggered by remote attackers through long command lines at port 32000 or certain name service queries that are not properly handled by the SMTP service.
Recommendations
For MERCUR Messaging 2005 versions prior to Service Pack 4, apply Service Pack 4 to resolve the issue. As a temporary workaround, consider restricting access to port 32000 and limiting the handling of name service queries by the SMTP service until the patch is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mercur Messaging 2005