SurgeMail Webmail "Host" Header Handling Denial of Service Vulnerability
Description
A vulnerability has been identified in SurgeMail, which could be exploited by remote attackers to cause a denial of service. This issue is caused by an input validation error in the webmail module when processing an overly long "Host" header, which could be exploited by remote attackers to crash a vulnerable server, creating a denial of service condiiton.
Vulnerable Products
Vulnerable Software: SurgeMail version 38k4 and prior