Microsoft Exchange 5.5 LDAP Denial of Service Vulnerabilities
BID:3045
Info
Microsoft Exchange 5.5 LDAP Denial of Service Vulnerabilities
| Bugtraq ID: | 3045 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2001-1319 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 16 2001 12:00AM |
| Updated: | Jul 11 2009 06:56AM |
| Credit: | This vulnerability was discovered using the PROTOS project's LDAPv3 test suite. Test results were published in a CERT Security Advisory on July 16, 2001. |
| Vulnerable: |
Microsoft Exchange Server 5.5 SP4 Microsoft Exchange Server 5.5 SP3 Microsoft Exchange Server 5.5 SP2 Microsoft Exchange Server 5.5 SP1 Microsoft Exchange Server 5.5 |
| Not Vulnerable: | |
Discussion
Microsoft Exchange 5.5 LDAP Denial of Service Vulnerabilities
Exchange Server is an email and directory server offered by Microsoft. The LDAP component of Exchange Server reportedly contains a vulnerability that can be exploited to cause a denial of service.
This problem was discovered using the PROTOS project's LDAPv3 test suite, which tests the security of a server by presenting it with a wide variety of sample packets containing unexpected values or illegally formatted data.
Exchange Server is an email and directory server offered by Microsoft. The LDAP component of Exchange Server reportedly contains a vulnerability that can be exploited to cause a denial of service.
This problem was discovered using the PROTOS project's LDAPv3 test suite, which tests the security of a server by presenting it with a wide variety of sample packets containing unexpected values or illegally formatted data.
Solution / Fix
Microsoft Exchange 5.5 LDAP Denial of Service Vulnerabilities
Solution:
Microsoft is reportedly working on a hotfix which will be released shortly.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Microsoft is reportedly working on a hotfix which will be released shortly.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.