PT-2010-4125 · Mailenable · Mailenable

Soroush Dalili

·

Published

2010-09-15

·

Updated

2018-10-10

·

CVE-2010-2580

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions MailEnable versions 3.x through 4.25
Description The issue concerns the SMTP service in MailEnable, where it fails to properly check the length of certain parameters. This can be exploited by remote attackers to cause a denial of service, leading to a crash. The attack can be initiated by sending a long email address in the MAIL FROM command or a long domain name in the RCPT TO command. This triggers an unhandled invalid parameter error.
Recommendations For MailEnable versions 3.x through 4.25, consider restricting access to the SMTP service until a fix is available. As a temporary workaround, limit the length of email addresses and domain names that can be processed by the MAIL FROM and RCPT TO commands to prevent the denial of service.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-2580

Affected Products

Mailenable