Clearswift MAILsweeper for SMTP before 4.3.20 and MAILsweeper for Exchange...
Vulnerability Description
Clearswift MAILsweeper for SMTP before 4.3.20 and MAILsweeper for Exchange before 4.3.20 allows remote attackers to cause a denial of service via (1) non-ASCII characters in a reverse DNS lookup result from a Received header, which leads to a Receiver service stop, and (2) unspecified vectors involving malformed messages, which causes "unpredictable behavior" that prevents the Security service from processing more messages.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-3216
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27305
- http://www.osvdb.org/26739
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27303
- http://download.mimesweeper.com/www/TechnicalDocumentation/ReadMe_MSW_4%2C3%2C20.htm
- http://www.securityfocus.com/bid/18584
- http://secunia.com/advisories/20756
- http://www.osvdb.org/26738
- http://www.vupen.com/english/advisories/2006/2473
More from clearswift
View All →Affected Vendor
clearswift
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.