First published: Wed Apr 13 2005(Updated: )
Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server 2000 and 2003 allows remote attackers to execute arbitrary code via a crafted X-LINK2STATE extended verb request to the SMTP port.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange Server | =2000 | |
Microsoft Exchange Server | =2003 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0560 has a high severity due to the potential for remote code execution.
To fix CVE-2005-0560, you should apply the latest security updates provided by Microsoft for Exchange Server 2000 and 2003.
CVE-2005-0560 affects Microsoft Exchange Server versions 2000 and 2003.
CVE-2005-0560 is classified as a heap-based buffer overflow vulnerability.
CVE-2005-0560 can be exploited by remote attackers targeting the SMTP service on unpatched Exchange Server installations.