PT-2007-1702 · Microsoft · Exchange Server

Published

2007-05-08

·

Updated

2020-04-09

·

CVE-2007-0221

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Exchange Server 2000 SP3
Description The issue is related to an integer overflow in the IMAP support, allowing remote attackers to cause a denial of service by sending crafted literals in an IMAP command. This can also be exploited by sending specially crafted IMAP requests to a Microsoft Exchange Server configured as an IMAP server, causing the mail service to stop responding.
Recommendations For Microsoft Exchange Server 2000 SP3, consider restricting access to IMAP services until a fix is available. As a temporary workaround, avoid using the IMAP server functionality until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-0221

Affected Products

Exchange Server