VID |
18106 |
Severity |
30 |
Port |
25 |
Protocol |
TCP |
Class |
SMTP |
Detailed Description |
The relevant host is running a version of Kerio MailServer prior to 6.6.2. Kerio MailServer is an SMTP server with built-in antivirus and antispam functionality. Kerio MailServer versions prior to 6.6.2 are vulnerable to a remote denial of service vulnerability in the LDAP service. A remote attacker could exploit this vulnerability to cause the affected server to crash.
* Note: This check solely relied on the banner of the remote SMTP server to assess this vulnerability, so this might be a false positive.
* References: http://www.kerio.com/security_advisory.html#0812
* Platforms Affected: Kerio Technologies, Inc., Kerio MailServer versions prior to 6.6.2 Linux Any version Microsoft Windows Any version |
Recommendation |
Upgrade to the latest version of Kerio MailServer (6.6.2 or later), available from the Kerio MailServer Download Web page at http://www.kerio.com/kms_download.html |
Related URL |
CVE-2008-5760,CVE-2008-5769 (CVE) |
Related URL |
32863 (SecurityFocus) |
Related URL |
(ISS) |
|