SurgeMail Malformed Host Header Denial of Service Vulnerability
BID:26901
Info
SurgeMail Malformed Host Header Denial of Service Vulnerability
| Bugtraq ID: | 26901 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2007-6457 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2007 12:00AM |
| Updated: | May 07 2015 05:34PM |
| Credit: | rgod is credited with discovering this vulnerability. |
| Vulnerable: |
NetWin SurgeMail 38k4 |
| Not Vulnerable: | |
Discussion
SurgeMail Malformed Host Header Denial of Service Vulnerability
SurgeMail is prone to a remote denial-of-service vulnerability because the application fails to handle specially crafted HTTP POST requests
An attacker can exploit this issue to crash the affected application, denying service to legitimate users.
SurgeMail 38k4 for Microsoft Windows is vulnerable; other versions running on different platforms may also be affected.
SurgeMail is prone to a remote denial-of-service vulnerability because the application fails to handle specially crafted HTTP POST requests
An attacker can exploit this issue to crash the affected application, denying service to legitimate users.
SurgeMail 38k4 for Microsoft Windows is vulnerable; other versions running on different platforms may also be affected.
Exploit / POC
SurgeMail Malformed Host Header Denial of Service Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
SurgeMail Malformed Host Header Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
SurgeMail Malformed Host Header Denial of Service Vulnerability
References:
References: