PureMessage for Microsoft Exchange RTF Multiple Denial Of Service Vulnerabilities
BID:30881
Info
PureMessage for Microsoft Exchange RTF Multiple Denial Of Service Vulnerabilities
| Bugtraq ID: | 30881 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-7104 CVE-2008-7105 CVE-2008-7106 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 28 2008 12:00AM |
| Updated: | Jul 06 2016 02:17PM |
| Credit: | The vendor disclosed these issues. |
| Vulnerable: |
Sophos PureMessage for Microsoft Exchange 3.0 |
| Not Vulnerable: |
Sophos PureMessage for Microsoft Exchange 3.0.2 |
Discussion
PureMessage for Microsoft Exchange RTF Multiple Denial Of Service Vulnerabilities
PureMessage for Microsoft Exchange is prone to multiple remote denial-of-service vulnerabilities because the application fails to properly process certain messages.
An attacker may exploit these issues to crash the affected application, denying service to legitimate users.
PureMessage 3.0 is vulnerable; other versions may also be affected.
PureMessage for Microsoft Exchange is prone to multiple remote denial-of-service vulnerabilities because the application fails to properly process certain messages.
An attacker may exploit these issues to crash the affected application, denying service to legitimate users.
PureMessage 3.0 is vulnerable; other versions may also be affected.
Exploit / POC
PureMessage for Microsoft Exchange RTF Multiple Denial Of Service Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
PureMessage for Microsoft Exchange RTF Multiple Denial Of Service Vulnerabilities
Solution:
The vendor has released PureMessage 3.0.2 to address these issues. Please see the references for more information.
Solution:
The vendor has released PureMessage 3.0.2 to address these issues. Please see the references for more information.
References
PureMessage for Microsoft Exchange RTF Multiple Denial Of Service Vulnerabilities
References:
References: