vendor:
Messaging Server
by:
Nobuo Miwa
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Messaging Server
Affected Version From: Netscape Messaging Server 3.6SP2
Affected Version To: Netscape Messaging Server 3.6SP2
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
1999
Netscape Messaging Server Denial of Service Vulnerability
Netscape Messaging server will not de-allocate memory that is used to store the RCPT TO information for an incoming email. By sending enough long RCPT TO addresses, the system can be forced to consume all available memory, leading to a denial of service.
Mitigation:
Limit the number of RCPT TO addresses that can be sent to the server.