VID |
18104 |
Severity |
30 |
Port |
25 |
Protocol |
TCP |
Class |
SMTP |
Detailed Description |
The relevant host is running a version of Kerio MailServer prior to 6.3.1. Kerio MailServer is an SMTP server with built-in antivirus and antispam functionality. Kerio MailServer versions prior to 6.3.1 are vulnerable to a remote denial of service vulnerability in the LDAP service. A remote attacker could exploit this vulnerability to cause the affected server to crash.
* Note: This check solely relied on the banner of the remote SMTP server to assess this vulnerability, so this might be a false positive.
* References: http://forums.kerio.com/index.php?t=msg&th=10321&start=0 http://www.kerio.com/kms_history.html http://www.securityfocus.com/archive/1/454455/30/0/threaded http://www.frsirt.com/english/advisories/2006/4993 http://secunia.com/advisories/23364/
* Platforms Affected: Kerio Technologies, Inc., Kerio MailServer versions prior to 6.3.1 Linux Any version Microsoft Windows Any version |
Recommendation |
Upgrade to the latest version of Kerio MailServer (6.3.1 or later), available from the Kerio MailServer Download Web page at http://www.kerio.com/kms_download.html |
Related URL |
CVE-2006-6554 (CVE) |
Related URL |
21091 (SecurityFocus) |
Related URL |
30872 (ISS) |
|