SurgeMail Webmail "Host" Header Handling Denial of Service Vulnerability


Description   A vulnerability has been identified in SurgeMail, which could be exploited by remote attackers to cause a denial of service. This issue is caused by an input validation error in the webmail module when processing an overly long "Host" header, which could be exploited by remote attackers to crash a vulnerable server, creating a denial of service condiiton.
     
Vulnerable Products   Vulnerable Software:
SurgeMail version 38k4 and prior
     
Solution  
     
CVE   CVE-2007-6457
     
References   http://retrogod.altervista.org/rgod_surgemail_crash.html
     
Vulnerability Manager Detection   No
     
IPS Protection  
ASQ Engine alarm Available Since
Possible buffer overflow in HTTP request/reply
3.2.0
     


 
 
 
 
 Risk level 
Low 

 Vulnerability First Public Report Date 
2007-12-18 

 Target Type 
Server 

 Possible exploit 
Local & Remote