CVE-1999-1504: Medium severity Stalker Stalker Internet Mail Server vulnerability

Published Apr 8, 1998
·
Updated

Stalker Internet Mail Server 1.6 allows a remote attacker to cause a denial of service (crash) via a long HELO command.

Affected Software

1 affected component
Stalker Stalker Internet Mail Server=1.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Stalker Internet Mail Server from your environment.

    Uninstall Stalker Internet Mail Server if SMTP functionality is not required, and replace it with an alternative mail server that is not affected.

  2. Configuration

    Stop or disable the SMTP service on the Stalker Internet Mail Server until a vendor patch or fix is available to prevent crashes caused by long HELO commands.

    Stalker Internet Mail Server SMTP service = disabled
  3. Compensating control

    Restrict network access to the SMTP service (e.g., port 25/587) using firewall rules or ACLs so only trusted IPs or internal mail relays can connect, preventing remote attackers from delivering long HELO commands.

  4. Compensating control

    Place an SMTP gateway/proxy or WAF in front of the server to validate and reject or drop HELO/EHLO commands that exceed expected lengths or are malformed, blocking exploit attempts before they reach the Stalker server.

Event History

Apr 8, 1998
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Sep 12, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-1999-1504?

CVE-1999-1504 is classified as a denial of service vulnerability, allowing a remote attacker to crash the Stalker Internet Mail Server.

2

How do I fix CVE-1999-1504?

To address CVE-1999-1504, you should consider upgrading to a newer version of Stalker Internet Mail Server that has patched this vulnerability.

3

What systems are affected by CVE-1999-1504?

CVE-1999-1504 specifically affects Stalker Internet Mail Server version 1.6.

4

Can CVE-1999-1504 be exploited remotely?

Yes, CVE-1999-1504 can be exploited by an attacker remotely through the use of a specially crafted long HELO command.

5

What impact does CVE-1999-1504 have on my server?

Exploitation of CVE-1999-1504 can lead to a denial of service, causing the Stalker Internet Mail Server to crash and become unavailable.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203