Kerio MailServer Remote LDAP Denial of Service Vulnerability
BID:21091
Info
Kerio MailServer Remote LDAP Denial of Service Vulnerability
| Bugtraq ID: | 21091 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 15 2006 12:00AM |
| Updated: | Dec 15 2006 07:58PM |
| Credit: | GLEG Ltd is credited with the discovery of this vulnerability. |
| Vulnerable: |
Kerio Mailserver 6.2.2 Kerio Mailserver 6.1.3 Kerio Mailserver 6.0.10 Kerio Mailserver 6.0.9 Kerio Mailserver 6.0.5 Kerio Mailserver 6.0.4 Kerio Mailserver 6.0.3 Kerio Mailserver 6.0.2 Kerio Mailserver 6.0.1 Kerio Mailserver 6.0 Kerio Mailserver 5.7.10 Kerio Mailserver 5.7.9 Kerio Mailserver 5.7.8 Kerio Mailserver 5.7.7 Kerio Mailserver 5.7.6 Kerio Mailserver 5.7.5 Kerio Mailserver 5.7.4 Kerio Mailserver 5.7.3 Kerio Mailserver 5.7.2 Kerio Mailserver 5.7.1 Kerio Mailserver 5.7 .0 Kerio Mailserver 5.6.5 Kerio Mailserver 5.6.4 Kerio Mailserver 5.6.3 Kerio Mailserver 5.1.1 Kerio Mailserver 5.1 Kerio Mailserver 5.0 Kerio Mailserver 6.1.3 Patch 1 |
| Not Vulnerable: |
Kerio Mailserver 6.3.1 |
Discussion
Kerio MailServer Remote LDAP Denial of Service Vulnerability
Kerio MailServer is prone to a denial-of-service vulnerability due to a flaw when handling malformed network traffic.
Successful exploits will result in denial-of-service conditions.
Kerio MailServer is prone to a denial-of-service vulnerability due to a flaw when handling malformed network traffic.
Successful exploits will result in denial-of-service conditions.
Exploit / POC
Kerio MailServer Remote LDAP Denial of Service Vulnerability
The following exploit code demonstrates this issue:
The following exploit code demonstrates this issue:
Solution / Fix
Kerio MailServer Remote LDAP Denial of Service Vulnerability
Solution:
The vendor has released version 6.3.1 of the affected package to address this issue. Please see the references for more information.
Solution:
The vendor has released version 6.3.1 of the affected package to address this issue. Please see the references for more information.
References
Kerio MailServer Remote LDAP Denial of Service Vulnerability
References:
References: