Korean
<< Back
VID 18104
Severity 30
Port 25
Protocol TCP
Class SMTP
Detailed Description The relevant host is running a version of Kerio MailServer prior to 6.3.1. Kerio MailServer is an SMTP server with built-in antivirus and antispam functionality. Kerio MailServer versions prior to 6.3.1 are vulnerable to a remote denial of service vulnerability in the LDAP service. A remote attacker could exploit this vulnerability to cause the affected server to crash.

* Note: This check solely relied on the banner of the remote SMTP server to assess this vulnerability, so this might be a false positive.

* References:
http://forums.kerio.com/index.php?t=msg&th=10321&start=0
http://www.kerio.com/kms_history.html
http://www.securityfocus.com/archive/1/454455/30/0/threaded
http://www.frsirt.com/english/advisories/2006/4993
http://secunia.com/advisories/23364/

* Platforms Affected:
Kerio Technologies, Inc., Kerio MailServer versions prior to 6.3.1
Linux Any version
Microsoft Windows Any version
Recommendation Upgrade to the latest version of Kerio MailServer (6.3.1 or later), available from the Kerio MailServer Download Web page at http://www.kerio.com/kms_download.html
Related URL CVE-2006-6554 (CVE)
Related URL 21091 (SecurityFocus)
Related URL 30872 (ISS)