CipherTrust IronMail Remote Denial Of Service Vulnerability
BID:16465
Info
CipherTrust IronMail Remote Denial Of Service Vulnerability
| Bugtraq ID: | 16465 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 01 2006 12:00AM |
| Updated: | Feb 07 2006 08:56PM |
| Credit: | Mark Ludwik is credited with the discovery of this vulnerability. |
| Vulnerable: |
CipherTrust IronMail 5.0.1 CipherTrust IronMail 6.0 CipherTrust IronMail 5.0 |
| Not Vulnerable: | |
Discussion
CipherTrust IronMail Remote Denial Of Service Vulnerability
IronMail is prone to a remote denial-of-service vulnerability. This issue is due to an error in the device when dealing with SYN flood attacks.
A remote attacker can exploit this issue to cause the device to fail, denying service to legitimate users.
Further information from the vendor reports that this issue doesn'tcause the device to actually fail, but to enter a defensive posture to protect against further denial-of-service attacks. However, this denial-of-service feature does remain in a defensive state for a prolonged period of time after the initial attack has subsided.
IronMail is prone to a remote denial-of-service vulnerability. This issue is due to an error in the device when dealing with SYN flood attacks.
A remote attacker can exploit this issue to cause the device to fail, denying service to legitimate users.
Further information from the vendor reports that this issue doesn'tcause the device to actually fail, but to enter a defensive posture to protect against further denial-of-service attacks. However, this denial-of-service feature does remain in a defensive state for a prolonged period of time after the initial attack has subsided.
Exploit / POC
CipherTrust IronMail Remote Denial Of Service Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
CipherTrust IronMail Remote Denial Of Service Vulnerability
Solution:
The vendor has released an update to address this issue. Contact the vendor for further information.
Solution:
The vendor has released an update to address this issue. Contact the vendor for further information.
References
CipherTrust IronMail Remote Denial Of Service Vulnerability
References:
References:
- IronMail Homepage (CipherTrust)
- IronMail-5.0.1-Denial of-Service-Protection-Lets-Remote-Users-Deny-Service (Mark Ludwick)