MAILsweeper for SMTP/Exchange reverse DNS denial of service
| mailsweeper-reverse-dns-dos (27303) |
Description:
MAILsweeper for SMTP/Exchange is vulnerable to a denial of service caused by improper handling of reverse DNS lookups by the receiver service. A 'Received' header in an email message containing non-ASCII characters could cause the service to stop responding when performing a reverse DNS lookup. A remote attacker could exploit this vulnerability by sending a malicious email message containing a specially-crafted 'Received' header with non-ASCII characters to cause the service to stop responding.
Consequences:
Denial of Service
Remedy:
Upgrade to the latest version of MAILsweeper for SMTP/Exchange (4.3.20 or later), available from the Clearswift Limited Web site. See References.
References:
- Clearswift Limited Web site: ReadMe for MAILsweeper 4.3_13 (Technology Update Version 1.4_13).
- MIMEsweeper Web site: ReadMe for MAILsweeper for SMTP 4.3.20.
- BID-18584: Clearswift MAILsweeper for SMTP / Exchange Multiple Vulnerabilities
- CVE-2006-3216: Clearswift MAILsweeper for SMTP before 4.3.20 and MAILsweeper for Exchange before 4.3.20 allows remote attackers to cause a denial of service via (1) non-ASCII characters in a reverse DNS lookup result from a Received header, which leads to a Receiver service stop, and (2) unspecified vectors involving malformed messages, which causes unpredictable behavior that prevents the Security service from processing more messages.
- OSVDB ID: 26738: MAILsweeper for SMTP/Exchange Malformed Reverse DNS Data DoS
- OSVDB ID: 26739: MAILsweeper for SMTP/Exchange Malformed Mail Security Service DoS
- SA20756: MAILsweeper for SMTP/Exchange Multiple Vulnerabilities
- VUPEN/ADV-2006-2473: Clearswift MAILsweeper Multiple Denial of Service and Security Bypass Vulnerabilities
Platforms Affected:
- Clearswift MAILsweeper for Exchange 4.3.19 and prior
- Clearswift MAILsweeper for SMTP 4.3.19 and prior
Reported:
Jun 21, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
