PT-2007-7405 · Qk · Qk Smtp Server

Published

2007-12-28

·

Updated

2018-10-15

·

CVE-2007-6573

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions QK SMTP Server version 3
Description The issue allows remote attackers to cause a denial of service, resulting in the daemon crashing. This can be achieved through various means, including sending a long string in the (1) HELO, (2) MAIL FROM, or (3) RCPT TO command, or by sending a long string in the message after the DATA command.
Recommendations For QK SMTP Server version 3, consider restricting the length of input strings for the HELO, MAIL FROM, and RCPT TO commands, as well as the message sent after the DATA command, to prevent the daemon from crashing. As a temporary workaround, consider implementing rate limiting or input validation to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6573

Affected Products

Qk Smtp Server