SmarterTools SmarterMail HTTP Request Handling Denial Of Service Vulnerability
BID:28610
Info
SmarterTools SmarterMail HTTP Request Handling Denial Of Service Vulnerability
| Bugtraq ID: | 28610 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-1854 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 04 2008 12:00AM |
| Updated: | May 07 2015 05:30PM |
| Credit: | Matteo Memelli aka ryujin <[email protected]> |
| Vulnerable: |
SmarterTools SmarterMail 5.0 |
| Not Vulnerable: | |
Discussion
SmarterTools SmarterMail HTTP Request Handling Denial Of Service Vulnerability
SmarterTools SmarterMail is prone to a denial-of-service vulnerability when handling specially crafted HTTP GET, HEAD, PUT, POST, and TRACE requests. When the server eventually resets the request connection, it will crash.
Remote attackers can exploit this issue to deny service to legitimate users.
SmarterMail 5.0 is vulnerable; other versions may also be affected.
SmarterTools SmarterMail is prone to a denial-of-service vulnerability when handling specially crafted HTTP GET, HEAD, PUT, POST, and TRACE requests. When the server eventually resets the request connection, it will crash.
Remote attackers can exploit this issue to deny service to legitimate users.
SmarterMail 5.0 is vulnerable; other versions may also be affected.
Exploit / POC
SmarterTools SmarterMail HTTP Request Handling Denial Of Service Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
SmarterTools SmarterMail HTTP Request Handling Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
SmarterTools SmarterMail HTTP Request Handling Denial Of Service Vulnerability
References:
References:
- Vendor Homepage (SmarterTools)