Vulnerabilities > CVE-2006-4616 - Remote Denial of Service vulnerability in Mailenable products

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
mailenable
nessus

Summary

SMTP service in MailEnable Standard, Professional, and Enterprise before ME-10014 (20060904) allows remote attackers to cause a denial of service via an SPF lookup for a domain with a large number of records, which triggers a null pointer exception.

Vulnerable Configurations

Part Description Count
Application
Mailenable
3

Nessus

NASL familySMTP problems
NASL idMAILENABLE_SMTP_SPF_DOS.NASL
descriptionThe remote host is running MailEnable, a commercial mail server for Windows. The SMTP server bundled with the version of MailEnable installed on the remote host is affected by a flaw in which SPF lookups for domains with large records may result in a NULL pointer exception in the SMTP service. An unauthenticated, remote attacker can exploit this issue to crash the affected service.
last seen2020-06-01
modified2020-06-02
plugin id22411
published2006-09-19
reporterThis script is Copyright (C) 2006-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/22411
titleMailEnable SMTP Connector Service SPF Record Crafted Lookup DoS