10
CVSSv2

CVE-2000-0971

Published: 19/12/2000 Updated: 19/12/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Avirt Mail 4.0 and 4.2 allows remote malicious users to cause a denial of service and possibly execute arbitrary commands via a long "RCPT TO" or "MAIL FROM" command.

Vulnerable Product Search on Vulmon Subscribe to Product

avirt avirt mail server 4.0

avirt avirt mail server 4.2

Exploits

source: wwwsecurityfocuscom/bid/1825/info Due to insufficient bounds checking in the code that handles the fields 'MAIL FROM:' and 'RCPT TO:', it is possible to remotely crash Avirt Mail Entering over 272 characters into the 'RCPT TO:' field will crash the application upon termination of the session and no further connections can be ini ...