First published: Fri Dec 31 2004(Updated: )
Clearswift MAILsweeper for SMTP before 4.3_13 allows remote attackers to cause a denial of service (infinite loop) via an e-mail with a crafted RAR archive attached.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Clearswift MAILsweeper | =4.3 | |
Clearswift MAILsweeper | =4.3.6 | |
Clearswift MAILsweeper | =4.0 | |
Clearswift MAILsweeper | =4.3.4 | |
Clearswift MAILsweeper | =4.2 | |
Clearswift MAILsweeper | =4.3.7 | |
Clearswift MAILsweeper | =4.3.3 | |
Clearswift MAILsweeper | =4.3.11 | |
Clearswift MAILsweeper | =4.3.13 | |
Clearswift MAILsweeper | =4.3.5 | |
Clearswift MAILsweeper | =4.1 | |
Clearswift MAILsweeper | =4.3.6_sp1 | |
Clearswift MAILsweeper | =4.3.8 | |
Clearswift MAILsweeper | =4.3.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2004-2328 is classified as a denial of service vulnerability due to an infinite loop caused by a specially crafted RAR archive.
To fix CVE-2004-2328, you should upgrade Clearswift MAILsweeper to version 4.3_13 or later.
CVE-2004-2328 affects Clearswift MAILsweeper versions prior to 4.3_13, including versions 4.0 to 4.3.12.
Yes, CVE-2004-2328 can be exploited remotely by sending a maliciously crafted email with a RAR attachment.
CVE-2004-2328 can cause affected systems to enter an infinite loop, resulting in a denial of service.