Korean
<< Back
VID 18106
Severity 30
Port 25
Protocol TCP
Class SMTP
Detailed Description The relevant host is running a version of Kerio MailServer prior to 6.6.2. Kerio MailServer is an SMTP server with built-in antivirus and antispam functionality. Kerio MailServer versions prior to 6.6.2 are vulnerable to a remote denial of service vulnerability in the LDAP service. A remote attacker could exploit this vulnerability to cause the affected server to crash.

* Note: This check solely relied on the banner of the remote SMTP server to assess this vulnerability, so this might be a false positive.

* References:
http://www.kerio.com/security_advisory.html#0812

* Platforms Affected:
Kerio Technologies, Inc., Kerio MailServer versions prior to 6.6.2
Linux Any version
Microsoft Windows Any version
Recommendation Upgrade to the latest version of Kerio MailServer (6.6.2 or later), available from the Kerio MailServer Download Web page at http://www.kerio.com/kms_download.html
Related URL CVE-2008-5760,CVE-2008-5769 (CVE)
Related URL 32863 (SecurityFocus)
Related URL (ISS)