vendor:
ActiveFax Server
by:
Achilles
7.5
CVSS
HIGH
Denial of Service (DoS) Local Buffer Overflow
CWE
Product Name: ActiveFax Server
Affected Version From: 6.92
Affected Version To: 6.92
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7 x64
2019
ActiveFax Server 6.92 Build 0316 – ‘POP3 Server’ Denial of Service
This exploit causes a denial of service (DoS) by creating a malicious payload and pasting it into the 'POP3 Server Address and Login and Password' field in ActiveFax Server 6.92 Build 0316. This leads to a crash in the application.
Mitigation:
Update to a patched version of ActiveFax Server to mitigate this vulnerability. Alternatively, restrict access to the 'POP3 Server' feature or disable it if not required.