vendor:
Free SMTP Server
by:
Metin Kandemir (kandemir)
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Free SMTP Server
Affected Version From: 2.5
Affected Version To: 2.5
Patch Exists: YES
Related CWE: N/A
CPE: //a:free_smtp_server:2.5
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 Service Pack 1 x64
2009
Free SMTP Server – Local Denial of Service Crash (PoC)
The SMTP Server will crash when a malicious code is run on localhost. The code creates a buffer of strings and sends them to the server, causing it to crash.
Mitigation:
Ensure that the SMTP server is running the latest version of the software and that all security patches are applied.