SLMail CPU Utilization Vulnerability
BID:221
Info
SLMail CPU Utilization Vulnerability
| Bugtraq ID: | 221 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Unknown |
| Published: | Feb 04 1999 12:00AM |
| Updated: | Feb 04 1999 12:00AM |
| Credit: | This vulnerability was posted to NTBugtraq by Marc <[email protected]>. |
| Vulnerable: |
Seattle Lab Software SLMail 3.0.2421 |
| Not Vulnerable: | |
Discussion
SLMail CPU Utilization Vulnerability
The POP service of SLMail (ESMTP) operates on tcp port 27. Issuing the 'helo' command followed by 819 to 849 characters can cause the server CPU to rise and stay at 90% utilization.
The POP service of SLMail (ESMTP) operates on tcp port 27. Issuing the 'helo' command followed by 819 to 849 characters can cause the server CPU to rise and stay at 90% utilization.
Exploit / POC
SLMail CPU Utilization Vulnerability
see discussion
see discussion
Solution / Fix
SLMail CPU Utilization Vulnerability
Solution:
Contact Seattle Labs (www.seattlelab.com) for a patch.
Solution:
Contact Seattle Labs (www.seattlelab.com) for a patch.
References
SLMail CPU Utilization Vulnerability
References:
References:
- eEye Digital Security Team Home Page (eEye)
- Seattle Labs Home Page (Seattle Labs)