Kerio MailServer Two Denial of Service Vulnerabilities

Monday, May 16 2005 @ 10:28 AM EDT

Two vulnerabilities have been reported in Kerio MailServer, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).

1) An error in the parsing of mails with multiple embedded ".eml" attachments may be exploited to crash the program on Linux systems.

2) An error when downloading mails for IMAP and KOC (Kerio Outlook Connector) can be exploited to cause a crash.

SOFTWARE:
Kerio MailServer 6.x

SOLUTION:
Update to version 6.0.10.
http://www.kerio.com/kms_download.html

VERIFY ADVISORY:
http://secunia.com/advisories/15360/

Secunia Security Advisories

0 comments



http://community.securityteam.us/article.php/20050516102859516