Korean
<< Back
VID 18085
Severity 30
Port 25
Protocol TCP
Class SMTP
Detailed Description The relevant host is running a version of Kerio MailServer prior to 6.0.9. Kerio MailServer is an SMTP server with built-in antivirus and antispam functionality. Kerio MailServer versions prior to 6.0.9 are vulnerable to a remote resource exhaustion vulnerability in the WebMail service. A remote attacker can send a specially crafted e-mail message to the target user. Then, when the target user views the e-mail message using the WebMail service, the service consume excessive CPU resources or crash.

* Note: This check solely relied on the banner of the remote SMTP server to assess this vulnerability, so this might be a false positive.

* References:
http://www.kerio.com/kms_history.html
http://www.securitytracker.com/alerts/2005/Apr/1013708.html

* Platforms Affected:
Kerio Technologies, Inc., Kerio MailServer versions prior to 6.0.9
Linux Any version
Microsoft Windows Any version
Recommendation Upgrade to the latest version of Kerio MailServer (6.0.9 or later), available from the Kerio MailServer Download Web page at http://www.kerio.com/kms_download.html
Related URL CVE-2005-1138 (CVE)
Related URL 13180 (SecurityFocus)
Related URL 20112 (ISS)