The SMTP service of MailEnable Standard 1.92 and earlier, Professional 2.0 and earlier, and Enterprise 2.0 and earlier before the MESMTPC hotfix, allows remote attackers to cause a denial of service (application crash) via a HELO command with a null byte in the argument, possibly triggering a length inconsistency or a missing argument.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2006-06-28 15:05
Updated : 2018-10-18 09:46
NVD link : CVE-2006-3277
Mitre link : CVE-2006-3277
JSON object : View
CWE
CWE-399
Resource Management Errors
Products Affected
mailenable
- mailenable_professional
- mailenable_enterprise