Lucene search

K
cve[email protected]CVE-2006-3216
HistoryJun 24, 2006 - 1:06 a.m.

CVE-2006-3216

2006-06-2401:06:00
web.nvd.nist.gov
23
cve-2006-3216
clearswift
mailsweeper
smtp
exchange
dos
vulnerability
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7 High

AI Score

Confidence

High

0.034 Low

EPSS

Percentile

91.5%

Clearswift MAILsweeper for SMTP before 4.3.20 and MAILsweeper for Exchange before 4.3.20 allows remote attackers to cause a denial of service via (1) non-ASCII characters in a reverse DNS lookup result from a Received header, which leads to a Receiver service stop, and (2) unspecified vectors involving malformed messages, which causes “unpredictable behavior” that prevents the Security service from processing more messages.

Affected configurations

NVD
Node
clearswiftmailsweeper_for_exchangeRange4.3.19
OR
clearswiftmailsweeper_for_smtpRange4.3.19

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7 High

AI Score

Confidence

High

0.034 Low

EPSS

Percentile

91.5%

Related for CVE-2006-3216