| VID |
18085 |
| Severity |
30 |
| Port |
25 |
| Protocol |
TCP |
| Class |
SMTP |
| Detailed Description |
The relevant host is running a version of Kerio MailServer prior to 6.0.9. Kerio MailServer is an SMTP server with built-in antivirus and antispam functionality. Kerio MailServer versions prior to 6.0.9 are vulnerable to a remote resource exhaustion vulnerability in the WebMail service. A remote attacker can send a specially crafted e-mail message to the target user. Then, when the target user views the e-mail message using the WebMail service, the service consume excessive CPU resources or crash.
* Note: This check solely relied on the banner of the remote SMTP server to assess this vulnerability, so this might be a false positive.
* References: http://www.kerio.com/kms_history.html http://www.securitytracker.com/alerts/2005/Apr/1013708.html
* Platforms Affected: Kerio Technologies, Inc., Kerio MailServer versions prior to 6.0.9 Linux Any version Microsoft Windows Any version |
| Recommendation |
Upgrade to the latest version of Kerio MailServer (6.0.9 or later), available from the Kerio MailServer Download Web page at http://www.kerio.com/kms_download.html |
| Related URL |
CVE-2005-1138 (CVE) |
| Related URL |
13180 (SecurityFocus) |
| Related URL |
20112 (ISS) |
|