PT-2007-7291 · Netwin · Surgemail

Published

2007-12-20

·

Updated

2018-10-15

·

CVE-2007-6457

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions SurgeMail version 38k4
Description The issue is a stack-based buffer overflow in the webmail feature, which can be exploited by remote attackers to cause a denial of service, resulting in a crash. This can be achieved by sending a long Host header.
Recommendations For SurgeMail version 38k4, consider restricting access to the webmail feature until a patch is available to prevent potential denial of service attacks. As a temporary workaround, limiting the length of the Host header may help minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6457

Affected Products

Surgemail