First published: Sat May 28 2005(Updated: )
The Data function in class.smtp.php in PHPMailer 1.7.2 and earlier allows remote attackers to cause a denial of service (infinite loop leading to memory and CPU consumption) via a long header field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHPMailer | <=1.72 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2005-1807 is considered high due to its potential to cause denial of service by exhausting system resources.
To fix CVE-2005-1807, upgrade PHPMailer to version 1.7.3 or later to eliminate the vulnerability.
CVE-2005-1807 enables remote attackers to conduct a denial of service attack through infinite loops caused by long header fields.
CVE-2005-1807 affects PHPMailer versions 1.7.2 and earlier.
The impact of CVE-2005-1807 is significant as it leads to high memory and CPU consumption, potentially crashing the server.